Cybersecurity

Users faked a nuclear plant in Iran using Google Earth AI — it was live for 24 hours

Adrian Kessler

Google Earth has spent two decades becoming the default visual reference for anyone trying to verify what the physical world actually looks like. Journalists use it to document conflict zones. Human rights researchers use it to track detention facilities. UN inspectors reference it from the safety of an office. Google briefly gave it something new: an AI image generator wired directly into the satellite map.

The tool, built on Nano Banana 2, Google’s own image-generation model, worked as advertised. Users typed a text prompt — ‘show Pompeii before the eruption’ or ‘turn this coastline into an infographic’ — and the AI overlaid generated imagery onto the corresponding real-world coordinates. Legitimate use cases were easy to imagine. The dangerous ones turned out to be just as easy to execute.

Henk van Ess, an investigative journalist, was among the first to document the problem. Within hours of the launch, he generated a fictitious nuclear power plant over a location in Iran. The result was convincing enough to illustrate the risk. More troubling was what happened when he tested the built-in safeguard: Google had embedded SynthID watermarks — the company’s AI authentication layer — in every generated image. Van Ess defeated it by photographing his screen rather than taking a screenshot. Third-party AI detection tools rated the resulting image just 1% likely to be AI-generated.

Google’s defense was technically accurate but practically inadequate. The company noted that generated images ‘didn’t appear in the main Google Earth experience for others to see’ — they were session-specific, visible only to the creator. That distinction collapses when you photograph the screen and share the result. A fabricated satellite image of a sensitive facility, circulating with nothing but a caption, is indistinguishable from one created to deceive.

There is a structural tension here that stronger guardrails may not fully resolve. The same capacity that makes AI image generation useful also makes it dangerous when the underlying source is trusted satellite data. That trust depends on the assumption that what Google Earth shows reflects physical reality. The moment generated content can be overlaid onto real coordinates — and the authentication layer defeated by a camera — that assumption has a crack in it that does not close when the feature goes offline.

The feature was pulled on July 31, less than 24 hours after launch. Google acknowledged seeing ‘screenshots of generated imagery that appear to violate our policies’ and committed to implementing ‘stronger guardrails’ before any relaunch. No timeline was given. The timing adds one more layer: as of August 2, the EU AI Act’s full enforcement provisions are in effect across Europe, making mandatory the labeling of AI-generated content that could deceive users — including, precisely, synthetic imagery embedded in trusted information sources.

Tags: , , , , ,

Discussion

There are 0 comments.