A Thursday launch, withdrawn by Friday

Joseph Cox of 404 Media typed a request into Google Earth and produced a blast crater in Los Angeles. Another prompt put a crowd of protesters outside Google's own campus in Mountain View. A writer at PC Gamer turned their hometown into a warzone. None of it had happened, and all of it sat on top of real satellite imagery of real places.

The feature was one day old. Google announced on 30 July 2026 that Nano Banana, its image generation model, could now create imagery grounded in Google Earth's satellite, aerial and 3D views. By 31 July the company had rolled it back and appended an update to its own announcement post.

The statement explaining the reversal reads: "We've seen geospatial professionals using this feature for a range of useful purposes, however we've also seen people sharing screenshots of generated imagery that appear to violate our policies. We're rolling back this feature in Google Earth while we work on implementing stronger guardrails." The trigger named in that sentence is worth holding on to. It was screenshots.

Every image carried the mark

This was not an unlabelled system. Every image the feature produced carried SynthID, Google's machine-readable watermark. Google's own update states that the generated images were watermarked as AI generated and that they did not appear in the main Google Earth experience where other people would come across them.

When first challenged, Google pointed at precisely that. Anyone could check an image using Gemini or Google Lens, and the company said it prevents image creation on harmful topics and updates its protections continually. On the technical claim Google was correct. The images were marked, the marking was detectable, and a route to verification existed for anyone who wanted one.

Cox's response was that this misreads how misinformation actually moves. People do not run the images they scroll past through a verification tool, and a caption travels faster than a provenance check. The mark was present in every file and consulted in almost none of them.

Brussels makes that mark the test on Sunday

Article 50 of the EU AI Act applies from 2 August 2026, which this year falls on a Sunday. It requires providers of AI systems, including general purpose systems, that generate synthetic audio, image, video or text to ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The duty is not restricted to high-risk systems, which is exactly why it reaches ordinary businesses.

The European Commission's guidance describes the required marks as effective, reliable, robust and interoperable, and sets no technical specification beyond that language. Exemptions cover assistive editing, source code, short sequences of symbols, machine-to-machine output and artistic, satirical or fictional work. Infringement is priced at up to 15 million euros or 3 percent of worldwide annual turnover.

Generative systems already placed on the market on 2 August have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2), a transition agreed in the AI Omnibus text of May 2026. Content generated before 2 August does not have to be labelled retrospectively. The United Kingdom has no equivalent statutory marking duty, so a British business is reached by this rule through what it publishes into the European market rather than through anything at home.

Compliance and safety turned out to be different questions

Run the two facts together and the result is uncomfortable. Google marked every output. Measured against the standard that binds providers from Sunday, the system passed. Google then withdrew it in under a day, because correctly marked images in circulation were doing the damage regardless.

A machine-readable mark is read by a machine that has been asked to look. In a screenshot pasted into a group chat, a social post or a slide deck, nothing asks. The mark survives as a property of a file that nobody interrogates, which makes it an excellent audit artefact and a weak defence. Article 50 sets the auditable version as the requirement, and Google has just demonstrated at global scale that meeting it is not the same as being safe to ship.

This is not an argument against the rule. Marking is a floor, and a floor is worth having, because without it there is no way to establish provenance even when someone does go looking. It is an argument against treating an Article 50 project as the end of the work. The largest company to deploy this technique in a consumer product satisfied the floor and still reversed itself inside 24 hours.

Three things to settle before Sunday

First, work out which side of the rule you are on. If you buy a generative tool, you are almost certainly a deployer, and the machine-readable marking duty sits with the provider. Your own obligation is different and more visible: disclose deepfakes, and disclose AI-generated or manipulated text published on matters of public interest where no person has reviewed it. That is a disclosure a reader sees, not a signal buried in a file.

Second, list every synthetic asset that leaves your organisation. Product renders, marketing imagery, training material, generated voice on a phone line, drafted copy on a public site. For each one, name who applies the mark, and get that in writing from the supplier rather than assuming the model handles it.

Third, run Google's test on your own output. Assume the asset is screenshotted, stripped of its metadata and reposted with a caption you did not write. If your answer to that scenario is that the file contains a watermark, you are holding the position Google held on Thursday and abandoned on Friday.