The idea was useful. The room it entered was not.

There is a real job here. A teacher may want to show what Pompeii could have looked like before the eruption. An architect may want to place a proposed building on its actual lot. A family may want to picture a backyard studio before paying for plans. Google’s launch post offered versions of all three.

The trouble was not that an AI image generator could fake a building. That was already possible. The trouble was placement. Google put the generator inside a product whose visual language means: this place exists, at these coordinates, and a camera or sensor recorded it.

Google says generated images never appeared in the main Earth experience for other users. They were separate outputs, not quiet edits to the shared base map. That distinction matters inside the product. It matters much less after somebody downloads the result, crops the frame and posts it elsewhere.

A concept inherits the credibility of the surface around it. Put a rough sketch on tracing paper and nobody mistakes it for a survey. Put the same idea under Google Earth’s colors, angle and coordinates, and it arrives with a reference source attached.

The abuse test took hours, not months

Independent investigator Henk van Ess tried the feature on the day it launched. He created a nonexistent nuclear plant in Iran, refugees near the US-Mexico border, a fatal crash in Amsterdam and a bomb crater beside a hospital in Gaza. He reported that none of those prompts was refused.

BBC Verify ran its own tests and generated a collapsed Eiffel Tower, a sinkhole at the Great Pyramid of Giza and Russian tanks in Kyiv. It also found that small wording changes could get around some harmful-content refusals.

Google’s first defense was specific: every image carried a SynthID digital watermark, people could ask Gemini or Lens whether an image was AI-generated, and harmful prompts were blocked. The first claim often worked in BBC Verify’s tests. The third did not hold up consistently.

Google then made the right immediate call. It rolled the feature back and said it would work on stronger guardrails. Fast reversals are better than defending a bad launch for a quarter. They are still a recovery metric, not evidence that the original release was ready.

A watermark only helps the person who checks

SynthID is not useless. Ars Technica asked Gemini to inspect several clean outputs from the feature and received a detection result. BBC Verify also found the check generally effective with images straight from Google Earth.

The weak point was the path an image actually takes. Ars photographed an altered image with a phone and could no longer get a verification result. Van Ess tested a screen recording with an outside detector; it missed the generated scene. BBC Verify found cases where external tools failed and where Gemini could be tricked into calling a fake image real.

That is the denominator I care about: not watermarks embedded, but forwarded images still identified. Test the exported file, a screenshot, a crop, a compressed copy from a messaging app, a screen recording and a phone photo of a screen. Publish how many remain detectable and how many genuine images are falsely flagged.

Then test people. Hand ordinary viewers a mixed set of real captures, clearly labeled concepts and reposted fakes. Can they tell which are generated in a few seconds? Do they know where to verify them? How often does a warning disappear before the image reaches the second person? Until those numbers exist, ‘watermarked’ describes an implementation, not an outcome.

If the feature returns, measure the journey out of Google Earth

A stronger prompt filter should begin with a fixed abuse set: conflict damage, troop movement, industrial accidents, border scenes, public landmarks and emergency events. Run direct prompts and paraphrases. Report the total tested, the refusals, the allowed harmless requests and the misses. A filter that blocks every community garden is safe in the least useful sense.

The export needs a visible label that stays attached after a crop or screenshot. An invisible watermark can back it up, but it should not be the only warning. The generated frame should look like a concept workspace, not the normal Earth viewer, and every saved image should carry a plain statement that it is synthetic.

Rollout shape matters too. The original image generator was announced as globally available to Earth web users. A smaller return could start with planners, teachers and designers who have named projects and an obvious reason to generate a concept. Watch what leaves the workspace before opening it to everyone.

My release check would fit on one page: harmful-request misses, harmless-request false blocks, provenance survival by sharing method, viewer identification rate and verification time. Google does not need to promise perfection. It needs to show where the warning breaks.

Ivy wants a concept room. Mina starts with the forwarded screenshot.

Ivy Chen does not want a useful visualization tool killed because it shipped in the wrong place. Her version lives in a clearly separate Concept Studio. Every export keeps a large synthetic label, the original coordinate and the prompt history. For client work, a named planner or designer owns the file before it leaves the project. That preserves the useful job without borrowing the authority of the base map.

Mina Torres begins later in the chain. A relative sends an alarming aerial image into a group chat at 11:40 p.m. There is no prompt history, no export panel and no reason for the recipient to know about SynthID. If the safety story is ‘open another Google product and ask,’ the checking work has been handed to the person with the least context and the most urgency.

Those positions pull in different directions. Ivy is willing to keep the tool if the generated mode is unmistakable and has an owner. Mina would judge it from the worst copy that reaches somebody outside Google Earth. The feature has to survive both tests.

How to check a suspicious satellite image now

First, find the earliest version you can. Ask who posted it, what location it claims to show, when the image was supposedly captured and which satellite or provider produced it. A dramatic crop with no date, coordinates or source is a claim, not evidence.

Run the image through Google’s verification tools if you suspect Google AI made it. A positive SynthID result is useful. A negative result proves only that the tool did not find Google’s marker; it does not prove the scene is real or that another model was not used.

Then leave the generator’s ecosystem. Compare the location against a dated source such as Copernicus Sentinel-2 or Landsat, and look for a second independent capture when the claim is consequential. Check roads, roof lines, shadows and fixed objects. Van Ess described a viral fake of a damaged naval base that kept the same parked cars as the earlier genuine image. The cars did more work than an AI-detection score.

Finally, slow the share. If the image concerns a war, disaster or public emergency, look for reporting from organizations that can name the location, capture time and verification method. ‘I could not verify this’ is a complete answer. You do not owe a group chat instant certainty.

Some products should keep fiction in a different drawer

Creative AI tools are most useful when the reader knows they are looking at a proposal, draft or imagined scene. Maps, medical records, bank statements and security footage carry a different promise. Their ordinary interface is part of the evidence.

That does not mean generative features can never touch them. It means the synthetic version needs a separate room, a visible boundary and proof that the boundary survives export. A tiny experimental label inside the product cannot do that job once the image is circulating alone.

Google recognized the trust problem in its rollback statement: people uniquely trust Google Earth for a reliable view of the world. That trust is the asset to measure. If a future version saves planners ten minutes but makes everyone else spend longer checking whether the map is real, the feature did not create time. It moved the bill.