Who faces legal risk when AI fakes satellite images?
Google Earth's AI satellite-image generator was launched and pulled within a day, but the legal exposure it created did not roll back with it. This record assigns who carries that risk — generator, publisher, deployer, or relying litigator — under the EU AI Act's Article 50, US evidence-authentication doctrine, and state deepfake statutes.
- Jurisdiction
- EU; US federal; US state
- Court
- Various (EU regulatory context; U.S. federal/state courts)
- AI tool named
- Nano Banana 2 (Google Earth AI image generator)
- Ruling date
- Jul 31, 2026
- Source document
- View primary court order ↗
- Last verified
- Aug 4, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Google put AI image generation inside Google Earth on July 30, 2026, made it available worldwide with no waitlist, and announced a rollback the next day while it worked on “stronger guardrails.” As of August 4, 2026, the public posture was a pause, not a cancellation.[1]
The point is not that an image model made implausible disaster scenes. Image models do that every hour. The legal problem is that this one made them inside a mapping environment that lawyers, investigators, journalists, insurers, and corporate security teams still tend to treat as a check against rumor. During the brief launch window, reporters and investigators documented generated satellite-style scenes including a nuclear plant in Iran, a refugee camp at the U.S.-Mexico border, a Gaza hospital with a bomb crater, fires at Iran’s Kharg Island, a flooded U.S. Capitol, a collapsed Eiffel Tower, a sinkhole at the Great Pyramid, Russian tanks in Kyiv, an explosion at Mar-a-Lago, and a plane at One World Trade Center.[1][2][3][4]

That 24-hour record is enough to answer the practical legal question: risk attaches at more than one point in the chain. The generator or provider may face transparency duties. The publisher or deployer may face disclosure duties. A lawyer or litigant who relies on the image faces authentication and certification risk. A party that uses the image to move public perception, market behavior, or a counterparty’s decision may also create tort, fraud, securities, or state deepfake exposure, depending on the facts.
None of those outcomes is automatic. No court or regulator has yet squarely held that AI-generated satellite imagery of this kind is covered by a particular deepfake rule or inadmissible under a particular evidence doctrine. But after this incident, counsel no longer gets to treat the problem as hypothetical.
The guardrail problem was not just generation; it was verification
Google’s mitigation story depended in part on SynthID. The generated images carried a watermark that Google said could be read through Gemini or Lens. BBC Verify, however, reported that Gemini could be tricked into vouching for fake images, that some external AI-detection tools failed, and that prompt filters could be bypassed by using less specific wording.[2]
That matters more than the individual prompts. In ordinary image-generator coverage, the failure is that the model will produce a false thing. Here, the failure sits closer to the verification layer: a false thing appeared in the very interface a downstream reviewer might use to corroborate a claim. Henk van Ess’s formulation is the line likely to reappear in later disputes: “The forgery does not have to look convincing on its own. It inherits the credibility of the map it was born on.”[2]
That inherited credibility is what converts a product rollback into a record-preservation problem. If a corporate security team screens a port, a journalist checks a conflict-zone claim, an insurer reviews flood damage, or a litigator attaches imagery to a filing, the question will not be whether Google later paused the feature. It will be what system produced the image, what marks were present, what marks were checked, what the checker returned, and who treated the result as reliable.

Generator or provider: the EU marking question
The EU AI Act is the first obvious place to look, because Article 50 became applicable on August 2, 2026, immediately after the Google Earth launch-and-rollback window. Article 50(2) requires providers of AI systems that generate synthetic audio, image, video, or text content to ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the provision’s terms and exceptions.[5]
If a Google Earth image-generation feature is treated as an AI system generating synthetic image content, the provider-side issue becomes concrete: was the output marked in a machine-readable way, and was that marking effective enough for the statutory duty? SynthID may be relevant to that analysis. BBC Verify’s account of Gemini being tricked and outside tools failing does not, by itself, prove an Article 50 violation. It does, however, show why “we watermarked it” will not necessarily end the inquiry when the image moves into legal, emergency, or commercial channels.[2][5]
The fine tier is not decorative. Article 99(4)(g) provides for administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, for certain infringements of Article 50.[6] That figure should be stated conditionally here. It would matter only if the relevant authority concluded that the system, actor, conduct, and obligation fall within the provision.
For procurement and vendor-risk teams, this is the same species of problem that appears in broader Alphabet tool-reliability reviews: a feature can be pulled quickly and still leave customers needing evidence of what was available, what was generated, what warnings were shown, and what detection path was promised. Counsel reviewing a Google- or Gemini-dependent workflow should not stop at uptime or model capability. The contract file needs the marking representation, the detection method, the logging position, and the rollback notice.
Publisher or deployer: disclosure risk follows the use, not the model demo
Article 50 also creates a separate deployer problem. Article 50(4) requires deployers of an AI system that generates or manipulates image, audio, or video content constituting a deepfake to disclose that the content has been artificially generated or manipulated, with carve-outs including certain law-enforcement purposes and more tailored treatment for artistic, creative, satirical, fictional, or analogous works.[5]
The unresolved point is whether a given AI satellite image is a “deepfake” within the meaning of the provision and whether the relevant actor is a deployer for that use. A fake satellite view of tanks in Kyiv posted as a joke, a crisis-intelligence slide circulated inside a company, and an exhibit attached to a demand letter are not the same use case. The statutory text does not become simpler because the image is overhead rather than portrait-style.
That is where the publisher’s file becomes important. Who selected the image? Was it labeled as synthetic? Was it represented as current satellite imagery? Was it embedded in a product, a report, a news item, a client alert, a public statement, or a pleading? If the image moved through a verification environment before publication, the record should preserve that fact rather than flatten it into “AI image found online.”
The same confirmed-versus-reported discipline that applies to contested recordings and attributed AI evidence applies here. A careful memo does not say “satellite imagery shows” when the available record only supports “an AI-generated satellite-style image was produced inside Google Earth and later circulated.” That difference can decide whether the later fight is about a bad inference or a false representation.
Relying lawyer or litigant: authentication is the near-term U.S. risk
For U.S. litigation, the most immediate risk is not a new deepfake statute. It is evidence authentication. Federal Rule of Evidence 901(b)(9) allows authentication by evidence describing a process or system and showing that it produces an accurate result. That framework is already used to think about machine-generated evidence and Google Earth material.[7][8]
The existing Google Earth cases are not AI satellite-fake cases, and they should not be cited as if they are. They are useful because they show the weak point: a court may accept a map or image for one purpose while refusing to accept an embedded timestamp or dating inference when the proponent has not shown that the process produces an accurate result. In Ory v. City of Naperville, an Illinois appellate court excluded Google Earth timestamps where dating accuracy was not proven; in Jones v. Mattress Firm, a Texas appellate court likewise treated Google Earth timestamp evidence as requiring proper support.[8]
Synthetic satellite imagery makes that authentication burden sharper. The relevant process is no longer merely the capture, storage, and display of geospatial imagery. It may include an AI generation layer, watermarking, detection tools, prompt logs, account permissions, editing history, export metadata, and any later compression or reposting. If the proponent cannot describe that chain, the opposing party has a clean place to press.
| Question for counsel | Why it matters before filing |
|---|---|
| What system produced the image? | Authentication under a process-or-system theory depends on describing the process, not just recognizing the place depicted. |
| Was the image generated, edited, or merely displayed in the mapping tool? | A real satellite base layer and a synthetic overlay create different evidentiary problems. |
| What machine-readable mark or watermark was present? | A marking representation may support or undermine claims about artificial generation. |
| Which detection tools were used, and what did they return? | A failed or tricked detector is part of the chain, not a footnote. |
| Who verified the image before reliance? | Certification, sanctions, contempt, and disciplinary risk usually attach to the human signer or filer. |
Proposed Federal Rule of Evidence 707 would make that inquiry more explicit for machine-generated evidence. Public comment on the proposal closed on February 16, 2026, and the proposal would require a proponent to show that the machine-generated evidence is authentic and that the system produced a reliable output under the circumstances.[7] Whether and when that proposal becomes operative is separate from the present incident. Its importance is that the rules conversation is already moving toward process proof rather than visual familiarity.
Louisiana has already moved in the same direction for lawyer conduct. Act 250, effective August 1, 2025, imposes a reasonable-diligence verification duty for certain AI-generated content submitted to courts and creates potential contempt and disciplinary exposure.[7] That statute is not a national satellite-imagery rule. It is a warning about where responsibility lands: on the lawyer who submits or relies on the material, not only on the vendor that made the tool.
The lesson for a relying lawyer is operational. If satellite imagery matters to a pleading, injunction record, insurance dispute, sanctions motion, trade-secret investigation, environmental claim, or war-crimes submission, the file needs more than a screenshot. It needs source, acquisition path, generation status, metadata if available, verification steps, tool outputs, and a witness or custodian who can explain the process.
Precedent signals: public perception can move before correction catches up
The Google Earth incident was not the first warning that synthetic or manipulated geospatial-looking imagery can outrun verification. In May 2023, a fake image of an explosion near the Pentagon spread through RT and verified social-media accounts; the S&P 500 briefly fell about 0.3% before the Arlington County Fire Department denied that an incident had occurred.[9]
Earlier in 2026, Bellingcat’s Jake Godin documented fake satellite imagery of a damaged U.S. base in Bahrain circulating in Iranian media. NPR reported that the image was built on Google Earth imagery with Google AI, and that real imagery later showed the base had been damaged, but not in the way depicted.[1]
Those examples should not be overread. The Pentagon image did not create a lasting market shock, and the Bahrain example was a single precursor, not proof of frequency. They matter because they show the timing problem that lawyers inherit: a false visual claim can affect public perception, verification workflows, and market behavior before the denial or correction becomes the dominant record.
State deepfake statutes and tort claims are hooks, not settled answers
In the United States, state deepfake-disclosure statutes, defamation, false light, fraud, negligent misrepresentation, unfair-trade-practice theories, and market-based claims are the likely civil hooks when AI satellite imagery is used to mislead. The harder question is fit. Many deepfake laws were drafted with people, elections, pornography, endorsements, or campaign communications in mind. A synthetic overhead image of a facility, border crossing, refinery, military base, or courthouse may not land neatly in those categories.
The tort analysis will be fact-bound. A fake flooded plant used in a private acquisition memo raises different issues from a fake explosion posted to move a stock, a fake refugee camp used in fundraising, or a fake military deployment attached to a public accusation. The common questions are reliance, falsity, materiality, fault, causation, damages, and whether the defendant disclosed the artificial nature of the image.
Counsel should resist the temptation to label every synthetic satellite image a “deepfake” and stop there. The useful work is narrower: identify the statute or cause of action, identify the actor’s role, identify the representation made about the image, and preserve the proof that will show whether the recipient was being informed, entertained, warned, deceived, or induced to act.
Where the exposure sits now
As of Q3 2026, the responsibility map is assignable even where liability remains unresolved.
- Generator or provider: potential EU Article 50(2) marking exposure if the system and actor fall within the provision, with Article 99 fine consequences only if an authority finds a covered infringement.
- Publisher or deployer: potential Article 50(4) disclosure exposure where the content qualifies as a deepfake and the use is not covered by an exception or carve-out.
- Relying lawyer or litigant: authentication, certification, sanctions, contempt, and disciplinary risk if the image is used without a defensible source-and-process record.
- Commercial or public communicator: state-law, tort, fraud, and market-based exposure where a synthetic satellite image is used to induce belief or action without adequate disclosure.
The first court or regulator to address synthetic satellite imagery directly will set the edges. Until then, the safer assumption is not that every fake image creates liability. It is that every serious use of satellite imagery now needs a provenance file capable of surviving someone else’s authentication challenge.
Google’s rollback ended the immediate product availability. It did not roll back the risk created by placing synthetic imagery inside a trusted verification interface just as EU transparency duties became applicable and U.S. evidence doctrine was already tightening around machine-generated proof.
References
- Google adds AI to satellite images, raising fears of deepfakes in the sky, NPR, July 31, 2026
- Google's AI satellite image tool paused after fake images created, BBC News
- Google Earth’s AI Images, The Atlantic, July 2026
- Nano Banana 2 removed from Google, Digital Digging
- Article 50: Transparency obligations for providers and deployers of certain AI systems, Artificial Intelligence Act
- Article 99: Penalties, Artificial Intelligence Act
- Adapting the Rules of Evidence for the Age of AI, Quinn Emanuel
- Evidentiary Issues with Google Earth Images in Property Claims, Zelle
- Fake image of Pentagon explosion briefly sends jitters through stock market, AP
Related records
Tool profile
Browse tool evaluations →Governing regulation
The 2025 DACA Protection Bills, Provision by ProvisionPreventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →