Skip to content

Crime and JusticeSan Francisco5 min read

Ex-Google Engineer Convicted of Stealing AI Secrets for China

Former Google engineer Linwei Ding was convicted of stealing AI trade secrets to benefit Chinese companies. This marks the Justice Department's first AI-related economic espionage conviction.

Share

Topics

Former Google Engineer Convicted in Landmark Case Over Stolen AI Secrets Tied to China

San Francisco jurors convicted former Google engineer Linwei Ding today on 14 counts — seven counts of economic espionage and seven counts of theft of trade secrets — for stealing confidential AI hardware and software designs to benefit entities tied to China.

Key takeaways

  • Verdict: Linwei (Leon) Ding, 38, was found guilty on 14 counts (seven economic espionage, seven theft of trade secrets).
  • Stolen technology: Documents included designs for TPUs, GPUs, and SmartNICs intended to accelerate large AI workloads.
  • Scope: Prosecutors say Ding copied over 1,000 unique files (~14,000 pages) and removed more than 2,000 pages; the indictment focused on 105 central documents.
  • Penalties and next steps: Counts carry up to 15 years (espionage) and 10 years (theft); a status conference is scheduled for Feb. 3, 2026.

Main coverage

Details of the conviction

A federal jury in U.S. District Court in San Francisco found Linwei (Leon) Ding guilty on 14 counts: seven counts of economic espionage and seven counts of theft of trade secrets. The Department of Justice characterized the outcome as a milestone — its first conviction involving AI-related economic espionage charges. The conviction stems from allegations that Ding stole confidential Google technology to benefit entities linked to China.

What prosecutors said at trial

Federal prosecutors presented evidence that Ding began copying sensitive internal Google documents in May 2022, transferred files to personal cloud accounts, and took steps to disguise the activity and avoid detection by Google security systems. Trial evidence showed intent to benefit two entities controlled by the government of China by helping to develop an AI supercomputer and by working on R&D of custom machine learning chips.

The stolen material allegedly included both hardware and software designs used to run large AI workloads, covering Google’s TPU designs, GPU configurations, and SmartNIC network cards that optimize data flow for machine learning — technology central to fast, efficient AI training and deployment.

(Sources: The Register; Fox Business.)

Background and employment

Ding was hired by Google in May 2019 as a software engineer and worked on software to make GPUs run more efficiently for machine learning. He had access to Google’s supercomputing data center systems used to train and deploy advanced AI models, according to trial materials and reporting.

(Source: The Register; Fox Business.)

During his employment, Ding maintained relationships with two technology companies based in the People’s Republic of China. He traveled to China from Oct. 29, 2022, to March 25, 2023, and took part in investor meetings to raise capital for a company called Rongshu. By May 30, 2023, Ding had founded Shanghai Zhisuan Technology Co. Ltd. (“Zhisuan”) and became its CEO; Zhisuan announced plans to develop a cluster management system to accelerate machine learning workloads.

Ding also applied for a Chinese government-sponsored “talent plan” in which he wrote he planned to “help China to have computing power infrastructure capabilities that are on par with the international level,” according to reporting.

(Sources: The Register; Los Angeles Times.)

How the theft was discovered

Google security teams first noticed documents being moved when Ding uploaded files to a second personal Google Drive account while he was in China. Investigators found that he downloaded data to a personal computer in December 2023, less than two weeks before resigning from Google. Security footage and badge records showed that another employee scanned Ding’s building access badge to make it appear he was on site in the U.S. during dates when he was actually in China.

(Sources: The Register; Los Angeles Times.)

Federal investigation and charges

The FBI executed a search warrant on Jan. 6, 2024, and a grand jury returned an indictment on March 5, 2024. The 11-day trial concluded with a unanimous jury verdict finding Ding guilty on all 14 counts. Prosecutors say Ding copied more than 1,000 unique files — roughly 14,000 pages — and removed more than 2,000 pages of confidential material between May 2022 and April 2023; the case centered on 105 documents identified in the indictment.

(Sources: The Register; Fox Business; Help Net Security.)

“The verdict was the Justice Department’s first conviction on AI-related economic espionage charges, underscoring how emerging technology has become a target for theft and spying,” said DOJ and FBI officials following the verdict.
(Sources: DOJ press release; Los Angeles Times.)

Defense arguments

Ding’s defense lawyers argued that he never sold or used the information and that Google failed to properly protect the documents. The jury rejected those claims and found the government proved beyond a reasonable doubt that Ding intended to benefit China-based entities.

(Source: Fox Business.)

Each economic espionage count carries up to 15 years in prison; each theft count carries up to 10 years. Ding’s sentencing will follow federal procedures. A status conference is scheduled for Feb. 3, 2026, where the court will set further scheduling and sentencing timelines.

(Sources: The Register; DOJ press release.)

Implications for United States of America

The verdict highlights growing risks to American technology leadership and national security. Loss of proprietary know-how could weaken competitiveness and cost jobs, affecting manufacturing and service roles that support tech supply chains in rural communities. The case raises questions about background checks, travel monitoring, and insider threat programs at major tech employers.

Modern agriculture increasingly depends on AI-driven tools for precision planting, irrigation, and equipment maintenance; theft of core AI technology could slow innovation or raise costs for these tools, with ripple effects reaching family farms and rural service businesses. The conviction may spur bipartisan action on tighter controls for sensitive AI research, export rules for high-end chips, and funding for domestic chip manufacturing.

Local law enforcement and private companies may strengthen cooperation with federal investigators to guard against similar threats, and the public may view the verdict both as proof that companies and government can catch bad actors and as a warning that firms must better protect sensitive information.

Sources and further reading

Share

Topics

Aaron Yates

Aaron Yates is a law and crime writer covering criminal investigations, federal prosecutions, fraud, public safety and legal disputes across the United States. His reporting follows law-enforcement agencies, courts and government accountability, providing readers with clear context on major cases and the legal issues surrounding them.

Write to Aaron