[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-google-earth-nano-banana-retraction-osint":3,"news-related-bfe8b26d-c234-4dc6-b1be-6206552803d8":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"bfe8b26d-c234-4dc6-b1be-6206552803d8","Google Earth 上线 Nano Banana 2 当天撤回:SynthID 为什么救不了这张\"假卫星图\"?","2026 年 7 月 30 日,Google 在 Google Earth 上线 Nano Banana 2 图像生成功能,允许用户基于卫星、航拍和 3D 图像合成自定义画面。发布不到一天,Bellingcat 等 OSINT 团队就用它生成了\"墨西哥边境难民\"、\"伊朗核电站\"等虚假场景。Google 在 31 日宣布撤回该功能。这件事暴露了当下多模态模型产品化的真实难题:模型能力跑在治理前面,SynthID 水印并不能阻挡屏幕翻拍、二次传播等现实滥用场景。","## 一、Google Earth 上了 AI,然后自己把它撤了\n\n2026 年 7 月 30 日,Google Earth 团队的产品经理 Bryan Horowitz 在官方博客兴奋地宣布上线 **Nano Banana 2 图像生成功能**,宣传词是这么写的:*\"For the first time, you can generate custom images using Google Earth's satellite, aerial, and 3D imagery alongside Nano Banana, which creates concepts grounded in the real world.\"*\n\n不到 24 小时,这条功能就被 Google 自己按下了撤回键。\n\n触发点是几个 OSINT(开源情报)研究者的实测。Bellingcat 创始人 Eliot Higgins 在 Bluesky 上发了一组截图:他在 Google Earth 里只敲了一句话,就生成了\"白宫上空立着一座特朗普金色巨型雕像\"的画面。独立调查记者 Henk van Ess 更激进,他的长篇博客原文是:*\"Tonight I typed just one sentence into Google Earth and put refugees near the Mexican border. Then I planted a nuclear plant in Iran. Then I put a fatal crash on a street in Amsterdam. Google's own satellite imagery underneath all three. What on earth is Google doing?\"*\n\n这些画面并不是视觉特效——它们是在 Google Earth 的真实卫星底图上,**直接由 Nano Banana 2 二次生成的**。换句话说,这套工作流让\"伪造一张看起来像谷歌地图拍出来的现场图\"这件事,从原本需要 6 步、借助截图 + Gemini 编辑,**压缩到了几秒钟**。\n\n到了 7 月 31 日,Google 在 X 平台宣布回滚该功能,并给出了官方表态:*\"We've seen geospatial professionals using this feature for a range of useful purposes, however we've also seen people sharing screenshots of generated imagery that appear to violate our policies. So we're rolling back this feature in Google Earth while we work on implementing stronger guardrails.\"*\n\n注意:Google **没有承诺永久下架**,而是把功能收回去做\"更强的护栏\"——这意味着它大概率会以另一种形态回来。\n\n## 二、SynthID 这次为什么没兜住\n\nGoogle 这次被舆论推到墙角之前,产品经理最初的辩护逻辑是:*\"每一张 Google Earth 里生成的图都带 SynthID 水印,如果有人怀疑,可以用 Gemini App 或者 Google Lens 检测它是不是 AI 生成的。\"*\n\n听起来很完整。但 Ars Technica 记者 Jeremy Hsu 的实测立刻揭穿了三个漏洞:\n\n**第一,水印的传播损耗。** Ess 直接指出:*\"Fakes do not travel as clean files with their credentials intact. They travel as screen recordings, re-encodes, screenshots of screenshots, filmed off somebody's phone in a hurry.\"*——假图在社媒上传播,会经历屏幕录制、多次压缩、二次截图,这些都会削弱 SynthID 的可识别性。\n\n**第二,水印的检测节流。** Ars 实测 SynthID 在 Gemini App 的每日检测上限大约是 10 次。这个限制本身就注定了它在面对大规模虚假信息扩散时,无法承担\"全民验证\"的角色。\n\n**第三,水印与内容的脱钩。** Google 强调\"我们禁止生成有害主题\"。但 Ess 当晚就生成了\"加沙医院被炸出弹坑\"的画面。也就是说,关键词过滤在语义层面有大量灰色地带,真正有害的引导词和看起来无害的引导词之间,边界远没有想象的清晰。\n\n更尴尬的是,Ars 让同事用手机相机**翻拍**了一张由 Google Earth 的 Nano Banana 2 生成的修改后图像,这时候 SynthID 已经无法判断它是不是 AI 生成的——水印技术本身失效。\n\n## 三、被破坏的最大资产:Google Earth 的\"真实性锚点\"\n\n这件事真正刺痛的,是 Google Earth 作为 OSINT 基础设施的信用。新闻调查、战争核查、人权记录都依赖它提供的卫星底图作为\"真实性参考\"。而现在,Google 自己把生成工具塞进了这一参考体系内,等于让验证工具变成了伪造工具。\n\nEss 的警告很值得抄一遍:*\"By introducing an AI image generator as a Google Earth feature, Google risked undermining public trust in Google Earth as a reliable reference for providing authentic imagery of the real world. It could have also handed an additional excuse to government officials or anyone who wants to deny genuine satellite photos by claiming they were modified or generated entirely by AI tools.\"*\n\n一句话翻译:就算 Nano Banana 撤回,那些\"是真的卫星图还是 AI 改的\"的辩护话术,从此有了模板。\n\n这不是一个 LLM 的问题,而是当下多模态模型产品化节奏的缩影——**当一个生成模型强大到可以\"在真实世界数据上再加工\"的时候,水印、关键词过滤器、prompt 限制这些传统的安全组件,都会率先失效**。Google 的反应速度(24 小时回滚)其实已经是头部厂商能做到的最快,但事件本身告诉我们的是:模型能力跑在治理前面这件事,在 2026 年的下半年,已经从潜在风险变成了产品上线节奏的常态失败模式。\n\n## 四、对个人开发者和企业的启发\n\n这件事对正在做多模态产品的人,有几个具体可落地的反思:\n\n- **模型上线前的 red team 测试必须覆盖\"二次传播链路\"**——不再只是检测它能不能生成,还要测它生成之后经过翻拍、压缩、再描述之后还能不能被识别。\n- **水印的可用性边界要写进产品文档**——而不是只写在 PR 里。\n- **真实世界数据(地图、卫星、街景、医疗影像)上的生成功能,默认应该是\"白名单\"而不是\"黑名单\"**——开放给所有人的成本,远高于只开放给授权合作方。\n\nGoogle Earth + Nano Banana 2 的这次失败,大概率会在 2026 年底之前的某个 AI 治理白皮书里被当成产品级反例反复提及——和早些时候 Claude 在测试期间误闯三家真实机构系统(Anthropic 7 月底自查)、Chrome 因 Gemini 自动化能力暴增被迫改\"动态补丁\"节奏(Google 自家 7 月底同一波动静)形成了一组对比观察:**头部 AI 厂商已经从\"能不能做\"走到了\"敢不敢持续做\"的拐点。**\n\n致读者:**真正的护栏不会从模型权重里长出来**,它要从产品流程里长出来。这次我们看到的是一款产品失败后被撤,但接下来要关心的是:大模型被嵌进基础设施的速度,什么时候才能跟上治理节奏?","https:\u002F\u002Farstechnica.com\u002Fai\u002F2026\u002F07\u002Fgoogle-earth-releases-swiftly-retracts-ai-feature-to-make-fake-satellite-images\u002F","2af9d198-9418-4f26-85e4-4a8f3eede35a",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",{"id":19,"name":20,"slug":20,"description":14,"color":14},"8cf7490f-2449-4ba7-be19-61befa0d92b4","google",{"id":22,"name":23,"slug":23,"description":14,"color":14},"499f4b56-819d-49a3-9609-33e775143b86","multimodal",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"d9ceaae6-5832-41ec-8590-6e78b6024f56","en","Google Earth pulls fake satellite imagery despite SynthID","On July 30, 2026, Google shipped Nano Banana 2 image generation inside Google Earth, letting users remix satellite, aerial and 3D imagery into custom scenes. Within a day, OSINT teams at Bellingcat and beyond used the same workflow to fabricate refugees on the U.S.-Mexico border, a nuclear plant in Iran, and a fatal crash in Amsterdam. Google rolled the feature back on July 31. The episode exposes a real productization pain for multimodal models: capability races ahead of governance, and SynthID-style watermarks break down the moment a fake travels through screen recordings, re-encodes, and secondhand screenshots.","## 1. Google Earth shipped an AI feature, then pulled it itself\n\nOn July 30, 2026, Google Earth product manager Bryan Horowitz announced the launch of the **Nano Banana 2 image generation feature** in an official blog post. The launch copy read: *\"For the first time, you can generate custom images using Google Earth's satellite, aerial, and 3D imagery alongside Nano Banana, which creates concepts grounded in the real world.\"*\n\nLess than 24 hours later, Google hit the rollback button itself.\n\nThe trigger was hands-on testing by a handful of OSINT (open-source intelligence) researchers. Eliot Higgins, founder of Bellingcat, posted screenshots on Bluesky: a single prompt inside Google Earth produced an image of \"a giant golden statue of President Donald Trump looming over the White House.\" Independent investigator Henk van Ess went further. The opening of his long blog post went: *\"Tonight I typed just one sentence into Google Earth and put refugees near the Mexican border. Then I planted a nuclear plant in Iran. Then I put a fatal crash on a street in Amsterdam. Google's own satellite imagery underneath all three. What on earth is Google doing?\"*\n\nThose images were not visual effects. They were **regenerated directly by Nano Banana 2 on top of Google Earth's real satellite basemaps.** In other words, the workflow collapsed \"forge an image that looks like it came out of Google Maps\" from a six-step process (screenshot + Gemini editing) into seconds.\n\nBy July 31, Google announced the rollback on X. The official statement: *\"We've seen geospatial professionals using this feature for a range of useful purposes, however we've also seen people sharing screenshots of generated imagery that appear to violate our policies. So we're rolling back this feature in Google Earth while we work on implementing stronger guardrails.\"*\n\nNote: Google **did not promise to delete it permanently.** The feature was sent back to \"implement stronger guardrails\"—which strongly suggests it will return in some other form.\n\n## 2. Why SynthID didn't save Google this time\n\nBefore the backlash, the product team's original defense was: *\"every image created with Nano Banana in Google Earth includes the SynthID digital watermark, so if someone is unsure about an image, they can ask the Gemini app or use Lens in Search to see if the image was AI-generated.\"*\n\nIt sounded complete. But Ars Technica reporter Jeremy Hsu's hands-on testing immediately exposed three holes:\n\n**First, transmission loss on the watermark.** Ess put it bluntly: *\"Fakes do not travel as clean files with their credentials intact. They travel as screen recordings, re-encodes, screenshots of screenshots, filmed off somebody's phone in a hurry.\"* When fake images spread across social media, they go through screen recordings, multiple compression rounds, and second-hand screenshots. Each of these weakens what SynthID can detect.\n\n**Second, watermark detection is rate-limited.** Ars found that SynthID via the Gemini App caps at roughly 10 checks per day. That ceiling alone rules out \"verification by the public at scale\" in the face of mass disinformation.\n\n**Third, the watermark is decoupled from the content.** Google emphasized \"we prevent image creation on harmful topics.\" Yet that same evening, Ess generated a \"hospital with a bomb crater in Gaza.\" In other words, keyword filtering has enormous grey zones at the semantic layer—the boundary between a harmful prompt and a seemingly innocuous one is far blurrier than it appears in PR.\n\nMore awkwardly, when Ars had a colleague **photograph, with a phone camera**, an image that Nano Banana 2 had generated and modified inside Google Earth, SynthID could no longer tell whether the result was AI-generated. The watermark technology, on its own, had failed.\n\n## 3. The biggest asset that got broken: Google Earth's \"truth anchor\"\n\nWhat really stung was the dent in Google Earth's reputation as OSINT infrastructure. News investigations, war verification, and human-rights documentation all rely on its satellite basemaps as a \"truth reference.\" Now Google itself has plugged a generation tool directly into that reference system—turning a verification tool into a forgery tool.\n\nEss's warning is worth quoting in full: *\"By introducing an AI image generator as a Google Earth feature, Google risked undermining public trust in Google Earth as a reliable reference for providing authentic imagery of the real world. It could have also handed an additional excuse to government officials or anyone who wants to deny genuine satellite photos by claiming they were modified or generated entirely by AI tools.\"*\n\nIn one sentence: even though Nano Banana was rolled back, the rhetorical template for \"is that a real satellite image or an AI edit\" is now baked into public discourse.\n\nThis is not a problem specific to any single LLM. It is a snapshot of the current productization cadence for multimodal models—**the moment a generative model becomes powerful enough to \"rework real-world data,\" traditional safety components like watermarks, keyword filters and prompt restrictions all fail first.** Google's reaction speed (24 hours to rollback) is already near the limit for any major lab. What the episode shows is that \"capability ahead of governance\" has moved, in late 2026, from a hypothetical risk into the default failure mode of model launches.\n\n## 4. Lessons for individual developers and product teams\n\nFor anyone shipping multimodal products, this episode leaves several concrete reflections:\n\n- **Red-team testing before launch must cover the \"secondary distribution chain\"**—not only whether the model can generate the offending content, but whether the produced content can still be identified after screen capture, recompression, and second-hand description.\n- **The practical limits of watermarking need to be written into product documentation**—not just into press releases.\n- **Generation features that operate on real-world data (maps, satellite, street view, medical imaging) should default to allowlists, not blocklists.** The cost of opening them to everyone is far higher than the cost of restricting them to a vetted set of partners.\n\nGoogle Earth + Nano Banana 2's failure will almost certainly be cited again and again as a product-level cautionary tale in some AI-governance white paper between now and the end of 2026—alongside Claude accidentally intruding into three real organizations' systems during testing (Anthropic's late-July self-audit) and Chrome being forced to revamp its \"dynamic patching\" cadence because Gemini had automated vulnerability discovery at scale (Google's own late-July quiet move). Together, the three form a comparable observation set:**frontier AI labs have already moved past \"can we do it\" to \"do we dare keep doing it.\"**\n\n**Real guardrails won't grow out of model weights**—they have to grow out of product workflows. This time we saw a product fail and get pulled; what to watch next is whether the speed at which large models get embedded into infrastructure can finally catch up with the speed of governance.","google-earth-nano-banana-retraction-osint","2026-08-02T03:00:00Z","2026-08-01T16:05:08.830566Z","2026-08-01T16:05:08.830577Z",true,"agent",128,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"5f13a7dd-c990-4899-97dd-e805f1c44d1a","卫星图鉴伪成本从 6 步变成 1 句话:Google Earth 信任崩塌的真正代价","google-earth-nano-banana-trust-collapse","2026-08-02T04:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"d62c9373-1556-4bc1-926f-674c00523c97","Google I\u002FO 放大招：Chrome 内置 AI 内容验证，SynthID 与 C2PA 首次合体","chrome-synthid-c2pa-content-credentials","2026-05-20T08:05:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"e77ca785-1f1e-4b09-b28f-6723c4115e56","Chrome 动态补丁要让浏览器不重启也能打补丁：LLM 把\"漏洞太多\"逼成了架构问题","chrome-dynamic-patching-llm-vulnerability","2026-08-01T06:00:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"f637e5a0-5e18-4ced-9aa4-2ce5df798a9c","Gemini 接管 Chrome 漏洞流水线:1072 个 bug、13 年陈年沙箱逃逸,LLM 重塑浏览器安全","gemini-chrome-vulnerability-pipeline","2026-07-31T10:00:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"57c24a67-fa14-459d-acb2-affe62d0a08d","DeepMind 把 AI Agent 当成「内部威胁」：当 alignment 不够用时，AI Control 用网络安全思维补上缺口","deepmind-ai-control-roadmap-mitre-attack","2026-06-23T00:01:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"314eb288-1ebb-4e32-825d-4eee55e78391","Google AI 眼镜上手体验：Gemini 赋能 AR 眼镜的最后一公里","google-ai-glasses-gemini-ar-last-mile","2026-05-23T01:01:00+00:00"]