Around July 10 and 11, 2026, as Typhoon Bavi approached China, the legal issue was not simply that people online were talking about the weather. Bloggers were reportedly using AI weather models to sell localized forecasts, including a prediction that Shandong had a “90% chance” of being affected. State media warned that amateur AI forecasts of this kind may be illegal because China’s Meteorology Law reserves public weather warnings to official meteorological stations.[1]
That detail matters. A paid, location-specific typhoon forecast expressed in probability language is not the same legal object as a casual post saying a storm looks serious. It can move through a public channel as risk information, be copied into group chats, be treated as an actionable warning, and compete with the official signal residents are supposed to rely on. The harder question for China’s AI weather-warning system is therefore not whether an AI model can forecast a storm. It is who is legally allowed to convert model output into a public warning.

The Bavi Warning Was a Distribution Problem
The Bavi episode should not be treated as a completed enforcement story. The available reporting supports a narrower conclusion: bloggers were warned that their amateur AI forecasts may violate meteorological law, and the incident exposed regulatory exposure. It does not establish that particular bloggers were prosecuted, sanctioned, or made into test cases.[1]
The legal pressure comes from the route the information took. A model output sitting in a private notebook is one thing. A paid forecast for a province during an active typhoon context is another. Once the output is packaged as a location-specific public forecast, the downstream reader has to decide whether it is official, reliable, actionable, and lawful. That reader is not helped by the fact that the forecast was generated by open-source code rather than a traditional forecasting office.
Article 22 of China’s Meteorology Law, as described in the SCMP account, is the first attachment point. It reserves the publication of weather forecasts and severe weather warnings to official meteorological stations. The reported consequence for unauthorized public forecasting includes warnings, orders to stop, and confiscation of illegal income.[1] The law’s concern is institutional authority over the public signal, not the elegance of the model behind it.
That distinction is easy to miss in AI discussions. If the debate is framed as “human forecaster versus AI forecaster,” the regulatory structure looks old-fashioned. If it is framed as “official warning channel versus unofficial public warning channel,” the structure becomes more legible. A weather warning is not merely a prediction. It is an instruction-like public communication that may affect travel, work, school, logistics, insurance decisions, emergency response, and public order.
Open-Source Forecasting Changes the Number of Potential Speakers
The reason the Bavi incident is not just another rumor-control story is that weather-generation capacity is no longer confined to state agencies, universities, or large commercial providers. People’s Daily reported that Fenghe, an open-source meteorological large language model, was launched on July 17, 2026, and trained on 50 million tokens.[2] Fengyuan, released in December 2025, points in the same direction: open-source meteorological AI is becoming part of the forecasting environment.
The point is not that every blogger in the Bavi incident used a specific newly released model. The point is structural: open-source meteorological tools lower the cost of producing outputs that look and sound like professional forecasts. Once a model can be downloaded, adapted, wrapped in a simple interface, and promoted through a social account, the regulated act can move away from the institutions the original meteorological framework expected to supervise.

This is where open source should be discussed carefully. Publishing a model is not the same act as issuing a typhoon warning. Experimenting with meteorological AI is not the same act as selling public risk forecasts. But a legal system built around centralized warning authority has to decide how far upstream it wants duties to travel when decentralized tools repeatedly produce downstream public warnings.
Where the Legal Exposure Attaches
The Bavi facts activate several overlapping regimes. They do not all attach to the same actor, and they do not all require the same misconduct. That is why the incident is useful for counsel: it separates model development risk, platform distribution risk, public-warning risk, AI-labeling risk, and false-information risk.
| Conduct | Likely legal question | Why Bavi matters |
|---|---|---|
| Private model testing or research | Is the actor providing a public meteorological service or merely developing a tool? | The available facts do not suggest that private experimentation alone was the target. |
| Publishing an open-source weather model | Do downstream uses create obligations for the publisher, platform, or service wrapper? | Open-source diffusion expands the pool of people able to create official-looking forecasts. |
| Selling localized typhoon forecasts to the public | Has the actor crossed into unauthorized public weather forecasting or warning? | The reported paid, location-specific Bavi forecasts sit close to the Meteorology Law concern. |
| Posting AI-generated forecast content without labels | Were AI-generated content labeling obligations triggered? | If AI output is disseminated as public content, labeling rules may add a separate compliance layer. |
| Spreading false disaster-related information | Does the content reach the threshold for false information liability? | Criminal exposure should be treated as an outer boundary, not assumed for every inaccurate forecast. |
The Meteorology Law point is the cleanest. If Article 22 reserves public forecasts and severe weather warnings to official meteorological stations, the unauthorized speaker’s problem is not solved by saying the model is open-source, experimental, or probabilistic. A “90% chance” forecast for a named province during a typhoon context may still function as a public forecast in the eyes of the audience and the regulator.[1]
Payment sharpens the issue. It gives the communication a service-like character and makes confiscation of illegal income more than a theoretical remedy. The available record does not support adding unsourced penalty amounts under the Meteorology Law, but it does support the conclusion that unauthorized income is legally relevant where amateur public forecasting is commercialized.[1]
Location specificity also matters. A general comment that AI models show possible storm movement may remain closer to commentary. A forecast aimed at Shandong, sold to users who may treat it as decision-grade information, looks more like a substitute warning channel. The closer the message gets to operational public guidance, the less persuasive it becomes to describe it as harmless model sharing.
Meteorology Law: authority over the warning signal
For lawyers advising platforms or AI developers, the first practical boundary is the line between discussing weather information and issuing public weather forecasts. The SCMP account places the state media warning squarely on the latter: amateur AI forecasts during Typhoon Bavi may be illegal because public weather forecasts and warnings are reserved to official meteorological stations under Article 22.[1]
The harder cases are not obvious hoaxes. They are semi-professional accounts that disclose an AI model, describe outputs as probabilistic, and avoid claiming government affiliation, while still selling or broadcasting localized risk predictions during live weather events. Those facts may reduce deception concerns, but they do not necessarily cure unauthorized-publication concerns.
AI labeling rules: transparency does not legalize the forecast
China’s AI labeling rules add a separate layer. White & Case’s AI regulatory tracker describes labeling obligations for AI-generated content, including rules effective September 1, 2025 that require explicit and metadata-embedded labels.[3] For an AI-generated weather post, failure to label can create its own compliance problem.
But labeling is not a safe harbor for unauthorized warnings. A post that says “AI-generated” may be more transparent than an unlabeled post, yet it can still compete with the official warning channel. The label tells the reader something about origin. It does not answer whether the speaker is legally authorized to publish a public weather warning.
AI Meteorological Measures: service review meets informal dissemination
The Measures for AI Meteorological Application Services, effective June 1, 2025 according to PreventionWeb’s summary, are the most directly targeted AI-weather instrument in the record.[4] The same summary describes obligations around AI meteorological application services, including information dissemination review and algorithm-related requirements.[4] Devdiscourse characterized the Measures as a first-of-its-kind regulatory move for AI meteorological services.[5]
Those summaries should be treated as secondary accounts, not as a substitute for direct review of the full Chinese-language legal text. Still, they show the regulatory logic: if AI is being used to provide meteorological application services, the service is not supposed to float outside administrative review merely because its output is algorithmic.
White & Case also notes broader Chinese AI and data-law penalty exposure, including possible penalties under frameworks such as the Cybersecurity Law, Data Security Law, and Personal Information Protection Law, with fines up to RMB 50 million or 5% of annual revenue in relevant circumstances.[3] That does not mean every amateur forecast triggers those maximum penalties. It means an AI meteorological service may sit inside a wider compliance stack if it involves algorithmic services, platform distribution, data processing, or unlabeled generated content.
The Measures help with formal providers. They are less obviously sufficient for fast-moving blogger conduct, small paid groups, repost chains, and model wrappers that appear during a public weather event. Centralized review works best when the regulated service is identifiable before dissemination. The Bavi pattern is harder: the public signal can be generated, sold, reposted, and acted on before a regulator has mapped who provided what.
Criminal Law Article 291: an outer boundary, not the default case
Criminal Law Article 291 is a potential outer boundary for spreading false information, with possible imprisonment of up to seven years. That possibility should not be flattened into a routine consequence for inaccurate AI weather posts. Criminal false-information exposure normally requires more than being wrong about a storm track; it turns on the nature of the false information, the dissemination, and the legally relevant harm or public-order consequences.
In the Bavi incident, the available material supports caution about possible illegality, not a conclusion that the criminal threshold was met. For compliance purposes, however, the outer boundary matters because disaster-related information can travel quickly and cause real-world reaction. An unauthorized AI forecast that is both false and widely disseminated is a different risk object from a mislabeled research chart.
The Gap Is Not a Lack of Rules
It is tempting to describe the Bavi incident as a regulatory gap. That is only partly right. China already has a centralized meteorological publication rule, AI content labeling obligations, AI meteorological service measures, and false-information law. The gap is more operational than textual: forecast-generation capacity is becoming decentralized, while authorization to issue public warnings remains centralized.
A traditional warning system assumes a small number of official broadcasters and a larger public audience. Open-source AI forecasting changes that geometry. The audience can become a forecaster, the forecaster can become a paid service provider, and the paid service provider can become a public warning channel without building anything that looks like a conventional meteorological institution.
That does not make open-source meteorological work suspect as such. There is real public value in transparent models, reproducible methods, and wider technical literacy. The problem begins when outputs leave the laboratory, repository, or commentary context and enter a channel where ordinary users may treat them as authoritative public risk instructions. At that point, the law’s interest is no longer limited to model accuracy.
For open-source model publishers, the practical implication is not that every release becomes a weather-warning service. It is that documentation, licensing language, interface design, and downstream-use warnings may become more important when the model is capable of generating public-safety information. A repository that enables meteorological forecasting is not automatically the same as a public warning channel, but the publisher should assume regulators and platforms will care about foreseeable misuse during emergencies.
For platforms, the risk is more immediate. A platform may see a post before it sees the model. It may need to distinguish general weather discussion from paid localized warning content, labeled AI output from unlabeled generated content, and official meteorological information from unofficial content that imitates official usefulness. In a live typhoon context, moderation delay can become part of the harm.
The Compliance Boundary Is Functional
The cleanest risk screen is functional rather than technical. Counsel should ask what the communication does in the hands of its audience. Does it tell the public that a specific place faces a specific weather risk? Is it timed to an active emergency or severe-weather event? Is it sold, promoted, or repeated as decision-useful information? Does it use probabilities, maps, alert colors, or wording that resembles official warning language? Is the speaker identified as unofficial, and is the AI origin labeled where required?
A hypothetical example shows the distinction. A developer posting model-evaluation notes that compare several historical storm tracks is likely to raise a different issue from a social-media account charging users for city-level typhoon impact predictions during an active storm. Both may involve AI. Only the second begins to look like a substitute public warning channel.
Media commentary sits somewhere between those poles. A journalist can report that official meteorological stations have issued warnings. A commentator can discuss how AI models are being used in forecasting. The danger starts when commentary adopts the form of an original public forecast, especially if it is localized, monetized, and detached from official meteorological authority.
The same analysis applies to disclaimers. “For reference only” language may help reduce reader confusion, but it does not necessarily prevent a post from operating as a warning. A user deciding whether to evacuate, cancel travel, or close a business may not parse the disclaimer with legal precision. Regulators looking at public-safety information are likely to care about how the communication functioned, not only how it was captioned.
Bavi as a Stress Test
Typhoon Bavi exposed a practical collision between centralized meteorological authority and decentralized AI capability. The reported blogger forecasts were legally important because they were public-facing, localized, probabilistic, and commercial in a live typhoon context. Those facts are enough to explain why state media framed amateur AI forecasting as potentially illegal under the Meteorology Law, even without confirmed sanctions.[1]
The current framework creates real exposure, but not a complete solution. The Meteorology Law controls who may issue public forecasts and severe weather warnings. AI labeling rules address transparency for generated content. The AI Meteorological Measures appear designed to bring AI meteorological application services into review and registration logic. False-information law remains an outer boundary for severe cases. None of those layers, by itself, fully solves the speed and scale problem created when open-source models let unofficial speakers generate official-looking risk information.
The compliance lesson is bounded but serious. Open-source AI model publishers, platforms, and counsel should not assume that public risk information remains legally neutral because the underlying model is open-source or the speaker is unofficial. Once an AI forecast becomes a public warning channel, Chinese law has multiple ways to ask who authorized it, who labeled it, who reviewed it, who profited from it, and who bore the consequences when the public treated it as real.
References
- Typhoon Bavi nears China, bloggers warned amateur AI forecasts may be illegal, South China Morning Post
- China launches open-source meteorological large language model, People's Daily, July 18, 2026
- AI Watch: Global regulatory tracker - China, White & Case
- Measures for AI Meteorological Application Services in China promulgated, PreventionWeb
- China sets global precedent with first AI meteorological services regulation, Devdiscourse
Comments
Join the discussion with an anonymous comment.