The Dutch Ministry of Defence in The Netherlands had ChatGPT make an emblem. The map of the Netherlands is wrong. Nobody noticed.
The emblem that rolled into my timeline
It did not start with the Ministry of Defence in The Netherlands. It started on my timeline. A lecturer in my network shared a new emblem for a partnership around air and missile defence and called it “unbelievably embarrassing” (LinkedIn user). A shield with a frigate, a fighter jet, a rocket launcher and a map of the Netherlands. At first glance, neatly done.

It belongs to something serious. On 4 June 2026 the Dutch Ministry of Defence in The Netherlands announced the creation of Gopin, the joint development and production partnership for Integrated Air & Missile Defence in the Netherlands. It brings together the Ministry of Defence, the Ministry of Economic Affairs, the NIDV, TNO, the NLR and participating universities. State Secretary Boswijk spoke of air defence that had been “catapulted from the background to the front lines” and called it “our scarcest asset”. The 2024 Spring Memorandum reserved hundreds of millions for it. This is not a side issue. This is national security.
So I asked the leadership a sober question: which tool was used to make this image? The answer came within minutes, publicly, from a brigadier general of the Dutch armed forces. One word: ChatGPT. And in the same thread he confirmed something else. No agency had been hired.
I asked my own AI what it noticed about the map
Before forming an opinion, I did what I advise every executive to do. I showed the image, neutrally, to my own AI assistant and asked what it noticed about the map of the Netherlands. The answer was sobering:
It is a recognisable silhouette, but geographically it is wrong. No clear IJsselmeer, no accurate Wadden Islands and internal lines that do not match the real provincial borders. A plausible-looking approximation, not a correct representation. That pattern, recognisable at a glance but wrong when you zoom in, is typical of maps produced by generative AI.
Read that again. The ministry that defends Dutch territory sent an image into the world on which that territory is wrong. Ironically, one detail was correct. Hull number F802 really does belong to HNLMS De Zeven Provinciën, an air-defence frigate. What already existed, the machine copied correctly. The map, it invented.
Which tool? “ChatGPT”, the leadership replied
That answer is unique and it is bigger than a picture. The leadership publicly confirmed that the image was made with ChatGPT. That makes it no longer an abstract risk but practice: a defence organisation used, as far as that public response shows, an American commercial AI service for the visual identity of a new air and missile defence partnership. Whatever you type into such an external service, you take outside your own controlled environment. For an average company that is already a data question. For a ministry of defence it touches sovereignty.
And that makes it bitter, because the ministry itself already has an answer to this. It built DefGPT, an internal alternative of its own that is completely cut off from the internet, precisely because sensitive input must stay within its own walls. According to an internal Defence estimate, employees previously used ChatGPT thousands of times a day. That was called a major risk, because sensitive information can end up in the open. Which is exactly why that public answer “ChatGPT” raises the question of why the external route was chosen for this output while a controlled one was within reach.
The work was internal. So was the failure.
And it happened in-house. No agency, the leadership itself confirmed. The people who made this are employed by the Ministry of Defence, not by a supplier. So this is not something that came from outside and was waved through unsuspectingly. It was made, approved and published within its own walls.
Here I want to be honest about what I can and cannot prove. I do not know exactly which internal review steps were taken. But I do know what the result shows: a map of the Netherlands that is wrong made it through the entire chain onto an official emblem. So either nobody actually checked that map, or the check was not expert enough to catch a visible error. This was not an obscure specialist detail. It was the map of the country itself. In both cases that is precisely the problem. The tool is not the only thing failing here. The review is failing.
Why this reminded me of the police
A few weeks earlier I was asked by Algemeen Dagblad and several regional newspapers about the Tilburg police. In a post about a burglary they had used AI images of arrests without disclosing they were fake, against their own rules. I called that extremely dangerous. Not to exaggerate, but because an organisation that constantly warns about deepfakes and disinformation cannot at the same time produce fake images itself. You undermine your own credibility.
At the Ministry of Defence I see exactly the same pattern and it carries more weight. With the police it was about trust. Here, sovereignty and national security come on top. The advice I gave the police, define when AI is and is not allowed, ensure monitoring and logging and ask not only whether something is permitted but whether it is desirable, applies here one to one. In fact, it applies here more urgently.
A wrong little map is not the problem, it is the warning
Because this is not about an ugly image. “A matter of taste”, the leadership responded to the criticism. That is exactly the wrong lens. A map that is wrong is not taste. It is a fact that is wrong, coming from the organisation that of all organisations should know.
In the past a designer took an existing, verified map of the Netherlands and placed it in the design. The source was known and correct. Now a model generates a map from a black box and the ministry turns out to be unable to judge it. The difference is not in the tool. It is in the loss of the ability to test an outcome against reality.
And that is where the real danger lies. A wrong little map you can still see. A manipulated answer that looks plausible, you cannot. The provider of such a tool knows its user, the account, the organisation. Anyone who compromises such a supplier or model chain, or who gains influence over the output through prompts and context, can in theory cause targeted deviations that look plausible to one specific organisation. With an emblem that is embarrassing at most. In an application that feeds into threat analysis or decision-making it is dangerous. The wrong map is then not the problem. It is the warning that the control is missing.
The questions nobody asked
Now that the leadership has publicly stated that it was made in ChatGPT, a series of questions presents itself that nobody answered. What was in the prompt? What else was discussed in that account? Was it a private or a business account and who paid for it? On which device? Where does that input end up and under which jurisdiction? For a ministry of defence, each of those questions is a problem in itself.
And this is not an isolated incident. In our book we describe shadow AI, the use of AI without the organisation knowing or governing it. Measurements at Dutch municipalities in 2025 showed ChatGPT to be by far the most used tool, alongside presentation makers such as Gamma.app into which civil servants upload documents containing sensitive resident data. Many of those tools are American, which means data can under certain conditions come within reach of American jurisdiction, such as via the CLOUD Act. Back then it was a measurement at municipalities. Now the Ministry of Defence confirms it in real life. The question is not whether that one little map was sensitive. The question is which other tools and agents are in use, with which data and whether there is central logging anywhere of who enters what.
When someone asked the priorities question, “where do our priorities actually lie” (LinkedIn user), the leadership answered with the mission: realising the partnership. Substantively that is correct. But it sidesteps the question. Mission and execution discipline are not opposites. An organisation that takes its air defence seriously takes precisely that small verification step seriously too. The one proves the other.
And here I get very concrete as an adviser. A government that deploys generative AI should log that use centrally: which tool is used, by which role or department, with which type of data and for which purpose. Not to distrust people, but to know as an organisation what is happening. Without that logging you cannot assess risk, reconstruct an incident or account for what happened. You simply do not know what has left your house.
Through the P-SEP lens
People is about the human who must be able to judge the outcome, because a reviewer who thinks “cool picture, go” is not control but a checkbox. And whoever removes the craftsman from the chain without replacing that knowledge organises the error instead of catching it.
Security is not about that one map but about the verification step missing underneath it, because the same absence of control that lets a wrong image through will later also let a manipulated or poisoned answer through in an application where you can no longer see the error with the naked eye.
Ethics counts that a government derives its authority from the fact that what it publishes is correct. Publishing an AI image without disclosure and silently replacing it later does not repair that credibility but erodes it further.
Privacy and sovereignty begin with the question of what ended up in the prompt and the account and under which jurisdiction that falls, because data typed into a foreign system is no longer only under your own control. And for a ministry of defence, “just quickly into ChatGPT” is not convenience but an operational and sovereignty risk.
In your organisation this means that the use of generative AI belongs on the boardroom table and not unseen in the browser, with the simple requirement that you know which tools are running, who may use them, with which data and who checks the outcome before it goes out.
Basics in order: for government that means a documented AI policy with central logging of all AI use, a secure internal environment as the standard and a mandatory, expert human review of every public output, not a luxury but the baseline.
Four recommendations for government
Four things every government working with generative AI can arrange now:
- Log all AI use centrally: which tool and which language model, by which role or department, with whose approval, with which type of data and for which purpose. Make sure all external consultants are fully logged as well.
- Run AI in your own, shielded environment under your own management, with active protection against prompt abuse and in-depth logging through a SOC. Note: a business cloud account, for example a paid ChatGPT account, is not your own management. Your data still runs at the supplier. Own management means the environment and the data stay within your own walls.
- Treat every new AI application as a new digital colleague and never bring one in without first holding it up to the P-SEP lens.
- Capture all of this in a professional AI policy that makes clear what is and is not allowed, who is responsible, which tools and language models are permitted, how logging is done and how every output is reviewed before it goes out. A policy that lives, not a document that disappears into a drawer.
In-house cyber resilience masterclass
Practical, no jargon and tailored to your organisation. By cyber expert and RESET! author Erik Jan Koedijk, trained by his late friend Kevin Mitnick, the world’s most famous hacker. In Curaçao, The Netherlands, Aruba, Bonaire, Barbados, Sint-Maarten, France, Belgium and the UK 3000+ professionals already joined the masterclasses hosted by Erik Jan.
Cyber resilience is not an IT topic. It is a team skill. In one inspiring four-hour session your people learn how attackers really work, how to recognise manipulation and how to protect the organisation and themselves, at work and at home. No technical background needed.
Tailored before we even start
Every masterclass begins with a thorough intake conversation. Together we map how your organisation communicates, where the human risks sit and what an attacker would try first. The social engineering exercises in the masterclass are then built on your reality, not on generic examples. Your people will recognise the situations, because these could happen tomorrow.
Learned from the master himself
Erik Jan was trained by his late friend Kevin Mitnick, the social engineer who proved that the easiest way into any organisation is through people. Those same techniques are demonstrated live in the masterclass, then turned into practical defences your team can apply the very same day.
You leave with more than awareness
Directly after the masterclass you receive a concrete overview of the processes in your organisation that can be tightened, based on what surfaced during the session. Not a generic checklist, but a starting point for real improvement, ready to discuss with your leadership team.
Included
✅ Intake conversation, so the social engineering exercises match your organisation
✅ Live demo: how freely available online tools reveal which systems expose your organisation, often without anyone knowing
✅ Inspirational knowledge quiz and a certificate for every participant
✅ Direct post-session overview of processes to tighten
✅ Private and in-house, exclusively for your organisation, with up to 20 participants per session
Book now: choose your preferred date and request more information.

