Why We Have No Defenses Against Satellite Deepfakes

Google has suspended the generation of artificial satellite scenes within Earth in less than a day. The case shows why watermarks and detectors aren't enough and how the verification of images used to document wars, disasters, and infrastructure must change.

It took Google just 24 hours to realize it had committed a madness: merging satellite reality and fiction in the same environment.

The world’s greatest engine of disinformation was born: a contamination of the basic wells of information, that is, those primary sources—for newspapers and activists—that are satellite imagery.

On July 30, 2026, Google introduced the “Create Image” command in the announcement of the new feature : the user framed a place on the web and described the event to be displayed.

On July 31, the company disabled it after screenshots circulated that violated its policies, announcing stricter controls. Some might ask: how is it possible that Google—after years of discussions about the ethical implications of deepfakes —didn’t consider the potential consequences sooner?

Tests reported by NPR and open-source researcher Henk van Ess showed nonexistent fires on the Iranian island of Kharg (perhaps a sign of a still-possible American attack), a U.S. Capitol surrounded by water, damage to hospitals, and accidents in urban areas. The feature was presented by Google as a creative tool, and it’s certainly not the only way to create fake images with AI.

Inserted into Earth, however, the function inherited the visual authority of a platform that journalists, analysts and citizens have been using for years to orient themselves, geolocalize content and compare the state of places.

A generalist generator can produce a fantastic scene without much ambiguity when the interface, format, and context clearly indicate it as such. On a planetary map, the same scene appears placed in real-world coordinates, alongside recognizable roads, ports, power plants, and borders. The screenshot retains these clues to authenticity and may lose the information that signals its generation.

Google recalled that the outputs contained SynthID , the imperceptible watermark developed by Google DeepMind and embedded in pixels to enable the recognition of synthetic content. The measurement is significant, but it answers a narrow question: can a compatible verifier detect the signal? An image circulating during a crisis raises further questions: who produced it, through what process, when, from what source, and what real-world event does it document?The technical distinction helps understand the gravity of the situation. A scientifically usable satellite image is the result of an acquisition chain: sensor, orbit or platform, time of passage, image geometry, spectral bands, resolution, radiometric calibration, processing level, and coordinate system. These elements allow us to measure, compare time series, and estimate uncertainty.

An AI-generated scene produces statistically plausible pixels. It hasn’t observed radiation reflected or emitted from the surface and doesn’t, by origin, possess the physical semantics of measurements. It can mimic smoke, craters, collapsed buildings, or an oil slick; it doesn’t provide the corresponding spectral or thermal evidence. Even Google Earth, it should be remembered, displays a visual composite from different dates and providers, not a live satellite feed. Generation adds a qualitative transformation: it introduces objects and events that don’t belong to any acquisition.

The problem was well known in research before the current wave of generative models. In the peer-reviewed study “Deep fake geography? When geospatial data encounter artificial intelligence ,” published in 2021 in Cartography and Geographic Information Science , Bo Zhao and colleagues at the University of Washington used generative networks to transfer urban features between Seattle, Tacoma, and Beijing. The work demonstrated both the plausibility of synthetic geographies and the ability to search for anomalies in color, texture, and the frequency domain. The methodological conclusion holds true: generation and detection evolve together, so a forensic clue effective against one model may lose strength against the next.

The greatest harm is the liar’s dividend.

The first consequence is the cheaper production of fakes. An operation that required compositing, geospatial knowledge, and time becomes accessible with a few words. Integration with the map automatically adds location, scale, and context—some of the elements that make alleged satellite evidence credible.

The second consequence concerns authentic images. In the essay “Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security,” published in 2019 in the California Law Review , Bobby Chesney and Danielle Citron defined the advantage gained by those who can dismiss real evidence as manipulation as a “liar’s dividend.” In the experiment “Deepfakes and Disinformation,” conducted on a quota sample of 2,005 British adults and published in 2020 in Social Media + Society by Cristian Vaccari and Andrew Chadwick , a deepfake political video tended to increase uncertainty and reduce trust in the news, even when it failed to deceive all participants. Applied to satellite imagery, the most dangerous outcome can be an environment in which each conflicting party has a ready denial: “it is generated.”

Speed ​​also matters. The study “The Spread of True and False News Online” by Soroush Vosoughi, Deb Roy, and Sinan Aral , published in Science in 2018 and based on approximately 126,000 stories shared on Twitter by approximately three million people between 2006 and 2017, found that fake news traveled farther, faster, and deeper than true news. The study did not involve satellite imagery, nor does it demonstrate that every fake follows the same dynamic. However, it documents an operational asymmetry: verification takes time, while an emotionally charged scene can reach the public before new acquisitions or independent verification are available.

Why SynthID and detectors are not enough.

Watermarking, forensic detection, and cryptographic provenance address different parts of the problem. The National Institute of Standards and Technology report, “Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency ,” published in November 2024, organizes countermeasures into complementary families: authentication and provenance, watermarking and labeling, synthetic content detection, and testing and auditing. The document highlights limitations, tradeoffs, and the need to combine techniques.

An embedded watermark like SynthID can withstand multiple transformations and allows the platform to recognize its output. Its absence does not certify that an image is real: the file may come from another generator, have been altered, or have undergone a transformation that renders the signal undetectable. Its presence demonstrates the generation or manipulation detected by the system, not the falsity of each element represented: a model may alter a real photograph or correctly display an event for accidental reasons.

Detectors that analyze pixel-level artifacts face a generalization problem. The scientific review “Media Forensics and DeepFakes: An Overview” by Luisa Verdoliva , published in 2020 in the IEEE Journal of Selected Topics in Signal Processing , describes an ongoing race between synthesis and analysis techniques. Compression, resizing, cropping, and switching between platforms alter the traces; new generators can produce distributions different from those used to train the detector. A probabilistic response, without knowledge of the model and the transformation chain, should not become a journalistic or judicial verdict on its own.

The signed provenance proposed by the Coalition for Content Provenance and Authenticity , a consortium developing an open technical standard for the origin and history of digital content, adds a verifiable record of changes. Here, too, precision is required: a valid credential certifies the claimed chain and the identity of the signer, not the truth of the event captured. A screenshot can also break the link with metadata, unless the system has durable mechanisms to recover it. Provenance reduces ambiguity in the chain; factual verification always requires external verification.

How an alleged attack occurs as seen from space 

The operational answer starts with the original, not the screenshot. The Berkeley Protocol on Digital and Open Source Investigations , published in 2022 by the Office of the United Nations High Commissioner for Human Rights and the Human Rights Center at the University of California, Berkeley, outlines principles for the collection, preservation, verification, and analysis of digital sources. Applied to remote sensing, they require a documented chain of evidence and corroboration between independent sources.

For a suspected fire in Kharg, the inspection should therefore search for the source image, the time of acquisition, the provider, and any multispectral data. Thermal anomalies can be compared with NASA’s public FIRMS system , which distributes active fire detections from MODIS and VIIRS. Sentinel-2 optical scenes and Sentinel-1 radar observations accessible from the Copernicus Data Space Ecosystem offer comparisons with different sensors and properties; radar can operate at night and penetrate clouds, but requires expertise to distinguish damage, water, roughness, and artifacts. Weather, wind direction, shadows, local news, and ground-based imagery complete the verification.

The absence of a signal from a single source doesn’t close the case. A satellite may have missed the right time, clouds may obscure the scene, a small fire may be below the sensor’s resolution, and near-real-time products have latencies. The correct conclusion must reflect the level of confidence and available evidence, avoiding both hasty authentication and automatic denial.

The AI ​​Act sets a minimum, security requires more.

The timing of the case also makes it relevant for Europe. Article 50 of the European Regulation on Artificial Intelligence , applicable from August 2, 2026, requires providers of systems that generate synthetic content to mark the output in a machine-readable format and detectable as artificial or manipulated; for deepfakes, it also imposes transparency obligations on those who use them, with the exceptions established by the law.

SynthID moves in the direction of required labeling. The Google Earth episode demonstrates the gap between information compliance and risk management. An invisible label only works if the recipient has the right tool, knows they need to use it, and receives a file in which the signal remains detectable. During the first hours of a crisis, many of the public sees screenshots compressed, cropped, or republished without context.

Geospatial platforms therefore require specific design.

Generative functions should exist in an environment visually separate from the observational view; each output should have persistent overt markup, even in clipping, along with verifiable credentials and a generation log. Limits are needed for high-risk sites and scenarios, adversarial testing conducted with OSINT investigators, rapid verification channels for newsrooms and authorities, prompt retention in cases of abuse, and response procedures that don’t rely solely on subsequent moderation.

Google Earth and the New Boundary of Geospatial Trust.

The rapid retirement prevented the feature from becoming a stable component of Earth, but the technical capability to produce satellite fakes remains available in many other tools. The lesson is the role of the interface: coordinates, cartography, and platform branding can give synthetic pixels a documentary appearance superior to that of a standalone generator.

Trust in geospatial evidence can only be sustained with a verifiable supply chain: identified acquisition, durable provenance, visible markings, access to original data, and comparison between independent sensors.

Journalists and analysts will have to treat every screenshot as a lead to be verified. Platforms that simultaneously host observation and generation, however, take on the additional burden of preventing the evidentiary force accumulated by the former from becoming a credibility multiplier for the latter.

We’re at year zero on all this. AI capabilities, however, are advancing. And big tech companies still don’t seem to be fully aware of their responsibilities.

Source: Digital Agenda. English translation by Google Translator.

In Primo Piano

Continua a leggere

Aumentano le morti sul lavoro nell’UE

Bruxelles – Nel 2024 sono morte 3.367 persone in incidenti sul lavoro nell’Unione europea, 45 in più rispetto all’anno precedente, con un aumento dell’1,4 per cento. È quanto emerge dagli ultimi dati di Eurostat, secondo cui nello stesso anno...

Minacce e attacchi informatici sul posto di lavoro per tre lavoratori su quattro nell’UE

Bruxelles – Tre dipendenti su quattro nell’Unione europea si sono scontrati con e-mail, messaggi o link sospetti sul luogo di lavoro. Sono i dati che emergono da un nuovo sondaggio Eurobarometro pubblicato oggi (30 settembre) dalla Commissione europea. Condotto...

How is the Mediterranean changing?

Spanish scientists and researchers from Europe and the US compiled data from 46 oceanographic campaigns carried out between 1976 and 2018 to study changes in the Mediterranean and the impact of climate change. Temperature, oxygen, pH, carbon and even the...