Share with your CISO
Google launched and then quickly pulled a feature called Nano Banana 2 in Google Earth that let users generate AI-altered satellite and aerial imagery with a simple text prompt. Researcher Henk van Ess at Digital Digging used it to produce convincing fake images depicting refugees near the Mexican border and a bomb crater beside a Gaza hospital before Google rolled the feature back. Google’s defense rested on SynthID watermarking, but van Ess demonstrated the watermark could be bypassed well enough to fool Hive’s AI detection tool.
What this means for your business
The organizations most exposed here aren’t the ones generating fake satellite images. They’re the ones whose analysts, operations teams, and intelligence workflows treat geospatial imagery as ground truth. If your company uses satellite or aerial imagery for site selection, supply chain monitoring, conflict-zone risk assessment, or physical security planning, the baseline assumption that “it came from a reputable platform” just got significantly weaker. The attack surface isn’t your systems; it’s your team’s epistemic habits.
Google’s SynthID response reveals a pattern that keeps recurring in AI product launches: the safety mechanism and the capability ship together, with the safety mechanism calibrated against benign misuse rather than adversarial misuse. SynthID is a steganographic watermark, meaning it hides a signal invisibly inside the image itself, and it works well when the recipient uses Google’s own verification tools. The problem is that adversaries don’t use Google’s tools to check their own fakes. Van Ess bypassed detection not through sophisticated cryptographic attack but through ordinary video export, and Hive’s detector, a widely used third-party content verification service, missed it. A watermark that only works inside the issuer’s own ecosystem isn’t a trust infrastructure; it’s brand protection dressed as one.
The decision this reframes isn’t whether to trust Google Earth specifically. It’s whether your organization has any verification protocol for geospatial imagery that doesn’t assume platform provenance. Cross-referencing against independent sources like Sentinel-2 or Landsat, both operated by the European Space Agency and NASA respectively with publicly auditable orbital metadata, is the verification discipline that should already exist. If it doesn’t, the next Nano Banana won’t need to come from Google to cause damage. I’d revise this assessment if Google ships a public API for SynthID verification that third-party platforms actually adopt at scale.
Concept deep-dive: Steganographic watermarking
Steganographic watermarking hides an invisible signal inside a digital file, the way a printer might embed a faint serial number in every page it produces. SynthID works this way on AI-generated images, encoding a detectable pattern into pixel values that survives most routine editing. The business limit is that detection requires the watermark reader, and if the reader is controlled by the same party that issued the watermark, independent verification collapses into vendor trust rather than technical proof.
Based on reporting from Here’s the problem with putting an AI image generator in Google Earth, originally published 2026-07-31 13:05:00.

