DevNews

Google Pulls Its Earth AI Image Tool One Day After Launch

On this page
  1. The context is the whole story
  2. The SynthID argument, and why it failed
  3. What this means if you are shipping generative features
  4. The state of it
  5. Sources and further reading

Google shipped a create image button in Google Earth on Thursday July thirtieth, letting anyone zoom to a coordinate, type a prompt and get a photorealistic image rendered onto that exact spot. It was gone in under 48 hours. The reason is the one you would predict: researchers and journalists demonstrated that fabricated scenes could be pinned to real world locations, and Google's answer, an invisible SynthID watermark on every output, did not hold up as a defence. That second part is the interesting one for anyone building with generative models, because it is a clean example of provenance metadata being technically present and practically useless.

The short answer

Google added a create image control to Google Earth on Thursday July thirtieth, powered by the Nano Banana 2 model, which generated photorealistic images pinned to any coordinate you navigated to. Researchers and journalists showed that fabricated scenes could be produced at real world locations, including conflict zone scenarios. Google initially pointed to the invisible SynthID watermark carried by every output as the safeguard, but BBC Verify testing found it bypassable in some cases. Google says it is rolling the feature back while it works on stronger guardrails, with no timeline offered.

48hfrom launch to rollback
SynthIDthe watermark defence, found bypassable in testing
No dategiven for the feature returning
Answer card: Google launched a Nano Banana 2 create image feature in Google Earth on July thirtieth 2026 and rolled it back within 48 hours after researchers showed fabricated scenes could be pinned to real coordinates, with the SynthID watermark defence shown to be bypassable.
Launched Thursday, withdrawn Friday. Source: Google's statement and contemporaneous reporting. PNG

The model was not new. Nano Banana 2 has been generally available since February and has generated a very large number of photorealistic images without anyone treating it as a problem. What changed on Thursday was where it was pointed.

The context is the whole story

Put an image generator in a standalone tool and its output carries no implicit claim about anything. Nobody looks at a generated landscape and assumes it is a photograph of somewhere.

Put the same generator inside a satellite mapping application, with the output rendered at a specific latitude and longitude, and it inherits two decades of accumulated assumption that Google Earth shows you a real place. The image does not have to assert anything. The interface asserts it on the image's behalf.

That transfer of credibility is the entire mechanism, and it is why the feature was in trouble immediately. Researchers and journalists demonstrated within hours that fabricated scenes could be produced at real coordinates, including scenarios in conflict zones. Google's own launch framing had been about landscape design and urban planning, and the company maintains that geospatial professionals were using it that way. Both things were true at once.

The SynthID argument, and why it failed

Google's first response was not to pull the feature. It was to point at provenance: every generated image carried a SynthID watermark, an invisible signature designed to survive screenshots and compression, and anyone could verify an image through the Gemini app or through Lens in Search.

Two problems, one technical and one structural.

The technical one is that BBC Verify's testing found the watermark bypassable in some cases. That is bad, but on its own it would be a bug to fix.

The structural one is the real problem, and it does not have a fix in the same category. A provenance signal only does work when somebody checks it. The path an image actually travels is: generated, screenshotted, cropped, posted, reshared. At no point in that chain does anyone stop to run a verification query, and the person who would most benefit from the check is by definition the person who has no reason to suspect they need one. An invisible watermark is a forensic instrument for an investigator who already has doubts. It is not a control on distribution.

Checklist figure contrasting provenance approaches for generated media: invisible watermarks like SynthID survive compression but require someone to actively verify and were found bypassable in testing, while visible on image labelling, generation time constraints on what can be produced, and limiting which surfaces can generate at all are enforced by default without any user action.
Where a provenance control sits in the pipeline decides whether it ever gets applied. PNG

What this means if you are shipping generative features

The useful lesson here is about placement in the pipeline, not about Google.

Provenance attached at generation time is opt in for the viewer. It requires a deliberate act by somebody downstream who has to first suspect something is wrong, then know that a verification tool exists, then go and use it. Every one of those steps loses most of the population.

Provenance enforced at display time is not opt in. A visible label burned into the pixels travels with the screenshot. A constraint on what the model will generate for a given prompt applies before anything exists to be shared. A restriction on which surfaces can generate at all, professional accounts only for example, limits the volume rather than trying to track it afterwards.

None of these are as elegant as an invisible signature, which is precisely why the invisible signature is attractive to build. The trade is that the elegant option only functions in the case where someone is already looking.

The state of it

Google's statement was that it had seen geospatial professionals using the feature for a range of useful purposes, that it had also seen people sharing generated imagery that appeared to violate its policies, and that it is rolling the feature back while it works on implementing stronger guardrails.

That is a pause, not a cancellation, and no timeline came with it. The interesting question for the relaunch is which layer the guardrails land on. If they arrive as prompt filtering, the same category of failure returns the first time someone finds a phrasing the filter does not catch. If they arrive as visible labelling on the rendered image, or as a restriction on who can generate at all, the property that made this feature risky actually goes away.

Sources and further reading

Frequently asked questions

What exactly did the feature do?

It added a create image control to Google Earth. You navigated to any location, typed a text prompt, and the Nano Banana 2 image model generated a photorealistic image rendered at those coordinates inside the map interface. Google's own launch post framed it around transforming a place, with landscape design and urban planning as the intended use cases, and the company said afterwards that geospatial professionals were in fact using it that way. The problem was never the capability in isolation. It was that the output arrived attached to a real coordinate inside an application whose entire value proposition is that what you see there is real.

What was SynthID supposed to do, and why did it not work?

SynthID is Google's invisible watermarking system, designed to embed a signature into generated images that survives screenshots, cropping and compression, so an image can later be identified as AI generated. Google's initial defence of the feature leaned on it: every output carried the watermark, and users could check an image through the Gemini app or Lens in Search. Two things broke that argument. BBC Verify testing found the watermark bypassable in some cases. And more fundamentally, almost nobody runs a verification step on an image they see in a feed. A provenance signal only works if it is checked, and the default path for a screenshot is that it is never checked.

Did Google say it would come back?

Yes, without a date. The company's statement was that it had seen geospatial professionals using the feature for a range of useful purposes, that it had also seen people sharing generated imagery that appeared to violate its policies, and that it was rolling the feature back while it works on implementing stronger guardrails. So the position is a pause for redesign rather than a cancellation. What stronger guardrails means in practice is undefined, and the range runs from prompt level filtering to visible on image labelling to restricting the whole capability to verified professional accounts.

Is this different from any other AI image generator?

The model is not the issue, and Nano Banana 2 has been generally available since February. The difference is context. A photorealistic image produced in a standalone image tool carries no implicit claim about where it was taken. The same image produced inside a satellite mapping application, positioned at a specific latitude and longitude, inherits that application's credibility. Google Earth spent twenty years establishing that what it shows you is imagery of a real place. Putting a generator inside that frame transfers the trust automatically, which is exactly the property that made the feature risky and that no watermark addresses.

What is the practical lesson for people building with these models?

Provenance has to be enforced at the point of display, not attached at the point of generation. A watermark embedded in a file is a forensic tool for someone who already suspects something and knows to check. It does nothing for the ordinary case, which is a screenshot in a group chat with the metadata layer stripped by the act of screenshotting. If your product generates synthetic content that could be mistaken for a record of reality, the durable controls are visible labelling burned into the pixels, constraints on what can be generated in the first place, and limiting the surface where output can be produced. Invisible signatures are a supplement to those, not a substitute.