Judge Overturns Half of Linwei Ding’s AI Secrets Convictions
- Sophie Larsen

- 4 days ago
- 14 min read
Google lost the economic espionage half of a landmark verdict, despite prosecutors securing 14 guilty findings against former engineer Linwei Ding in January. The latest google news is therefore a legal reversal, but not an exoneration. Ding still stands convicted on seven counts of stealing AI trade secrets.
U.S. District Judge Vince Chhabria ruled on August 20 that prosecutors had not proved a required connection to China’s government. Evidence could support findings that Ding intended to benefit himself, Chinese companies, or China more broadly. According to the judge, that was not enough to sustain seven economic espionage convictions.
The decision leaves a sharply divided result. The government proved criminal theft involving Google’s AI infrastructure, yet failed to prove the additional foreign-government element. That distinction now matters to prosecutors, AI companies, security teams, and employees handling sensitive technical material.
It also changes the meaning of a case the Justice Department had presented as a historic national security victory. Officials called January’s outcome the first U.S. conviction involving AI-related economic espionage. The underlying theft verdict survives, but that larger claim no longer describes the current judgment.
What Changed in the Ruling
Judge Chhabria removed all seven economic espionage convictions while preserving seven trade-secret theft convictions.
A federal jury reached its original verdict on January 29, after an 11-day trial in San Francisco. Jurors found Ding guilty on every count presented to them. The counts covered seven categories of Google information related to AI computing systems.
The Justice Department announced the result the following day. Its January verdict described more than 2,000 pages of confidential material taken from Google’s network. Prosecutors said Ding uploaded the material to a personal Google Cloud account.
The government divided its case between two federal crimes. Seven counts alleged theft of trade secrets under Section 1832 of the Economic Espionage Act. Seven parallel counts alleged economic espionage under Section 1831.
Those laws overlap, but they do not ask prosecutors to prove exactly the same thing. Trade-secret theft can involve an intended economic benefit for someone other than the information’s owner. Economic espionage requires an additional connection to a foreign government, instrumentality, or agent.
That extra requirement became decisive. In the August 20 ruling, Chhabria concluded that the government’s evidence did not establish the necessary intent or knowledge. Reuters reported that he found insufficient proof that Ding knew or intended his conduct would benefit China’s government.
The distinction is narrower than the headline may suggest. Chhabria did not find that the documents lacked trade-secret status. He did not overturn the jury’s conclusion that Ding stole them.
The judge also did not rule that Ding’s relationships with Chinese businesses were imaginary or irrelevant. Those connections supported the surviving theft case. They simply did not close the legal gap between benefiting a company in China and benefiting the Chinese state.
That makes “partially overturned” the essential phrase. Half the counts disappeared, including the charges carrying the case’s strongest national security label. The other half remain intact and cover the same seven groups of confidential AI information.
Each surviving trade-secret count carries a statutory maximum of 10 years in prison. Maximum penalties do not predict the eventual sentence, which depends on federal law and sentencing guidelines. Still, the remaining convictions expose Ding to substantial criminal consequences.
The ruling also revises a milestone that government officials emphasized after the trial. The Justice Department had described the verdict as the first conviction on AI-related economic espionage charges. After Chhabria’s ruling, the case remains an important AI trade-secret prosecution, but not that claimed first.
The outcome can still change through further litigation. Prosecutors can evaluate an appeal of the acquittal ruling, while Ding can continue challenging the surviving convictions. Until another court intervenes, however, the split judgment defines the case.
The AI Secrets at the Center of the Case
The surviving case concerns the computing architecture behind large AI systems, not ordinary product plans or general research notes.
Ding joined Google in 2019 and worked on software related to graphics processing units, according to the government. His authorized access included information about the hardware and software inside Google’s supercomputing data centers.
Prosecutors said the stolen material described Tensor Processing Units, or TPUs. A TPU is a Google-designed processor optimized for machine-learning calculations. The material also covered systems using graphics processing units, which train and serve many large AI models.
Other information concerned software that coordinates thousands of processors inside an AI supercomputer. That orchestration layer determines how chips communicate, share workloads, and operate as a larger computing system. It can affect training speed, reliability, and resource use.
The case also included details about SmartNIC technology. A SmartNIC is a network interface card that handles networking tasks with its own programmable computing resources. Google uses such components within cloud networks and AI infrastructure.
An early federal indictment identified specifications for TPU versions 4 and 6. It also listed GPU system information and software for managing machine-learning workloads. A later superseding indictment expanded the case to seven categories and added economic espionage charges.
The alleged transfer method was surprisingly ordinary. Prosecutors said Ding copied material from Google source files into Apple Notes on his company-issued MacBook. He then converted the notes into PDF files and uploaded them to a personal cloud account.
The original indictment said this process began in May 2022 and continued until May 2023. It identified more than 500 unique confidential files in the personal account. The Justice Department later described the trial evidence as covering more than 2,000 pages.
That method matters for security teams because it crossed several familiar boundaries. Sensitive content moved from internal sources into a general note-taking application. It then became a common document format before leaving through personal storage.
No exotic exploit was required. The alleged activity depended on legitimate employee access and transformations that made internal information easier to move. This is an insider threat, meaning a security risk created by someone with authorized organizational access.
Google’s detection also came late in the sequence described by prosecutors. Ding had already spent months uploading information before the company examined his network activity. The investigation accelerated after Google learned about his outside business role.
According to the indictment, Ding signed a declaration in December 2023 stating that he had removed Google’s nonpublic information from his personal possessions. Prosecutors alleged that he did not disclose the earlier uploads or his affiliations with two China-based businesses.
Google then learned that Ding had appeared as chief executive of his startup at an investor conference in Beijing. The company suspended his network access, remotely locked his laptop, and reviewed his activity history.
The FBI searched Ding’s home in January 2024. Investigators also obtained material from his personal accounts. The government’s case eventually connected the retained documents with his work for one startup and plans for another.
This sequence gives the remaining convictions their practical significance. The case was not built only around an employee possessing information beyond his last working day. Prosecutors presented a longer course of copying, concealment, outside business activity, and investor outreach.
Ding contested the government’s legal and factual theories. A conviction means the jury accepted the theft case beyond a reasonable doubt, subject to the judge’s later review. It does not make every government allegation an independently established fact.
The Government Link Was the Weak Point
The central reversal separates a proven plan to benefit outside businesses from an unproven plan to benefit China’s government.
Economic espionage carries a politically charged name, but its legal meaning is specific. Prosecutors must establish that a defendant intended or knew an offense would benefit a foreign government, foreign instrumentality, or foreign agent.
It is not enough to show that a foreign national stole valuable technology. A foreign company’s expected benefit also does not automatically satisfy the requirement. The government must prove the connection identified in the statute.
That issue was visible before trial. In a pretrial order in *United States v. Linwei Ding*, Case No. 3:24-cr-00141-VC, Chhabria rejected theories that would treat benefits to China or Chinese industry as sufficient by themselves.
The order explained that knowledge of a favorable government-created environment does not necessarily establish intent to benefit that government. Prosecutors still had to connect Ding’s contemplated benefit to the People’s Republic of China as a state.
At trial, the government presented several facts aimed at making that connection. Ding allegedly referenced Chinese policies supporting AI development in investor presentations. He also applied for a government-sponsored talent program in Shanghai.
The Justice Department said his application promised to help China develop computing infrastructure comparable with international capabilities. Prosecutors also asserted that two government-controlled entities would benefit from proposed supercomputer and chip-development work.
Those facts created a national context. Chhabria nevertheless found that they did not prove the required state benefit beyond a reasonable doubt. The ruling therefore applies a demanding line between government policy alignment and criminal intent.
That line can frustrate prosecutors in technology cases. Governments often support domestic companies through funding, procurement, industrial policy, research programs, or favorable regulation. A company’s success can advance national goals without making every benefit a legal benefit to the state.
The problem becomes harder in AI infrastructure. Chips, networking systems, and orchestration software have commercial and strategic uses at the same time. The technology can support private cloud services, state research, defense programs, or all three.
Prosecutors must still prove the defendant’s state-directed intent in the particular case. Broad geopolitical competition cannot substitute for evidence about a defendant’s knowledge and purpose.
The surviving trade-secret charges demanded a different showing. Prosecutors needed to prove that Ding knowingly misappropriated protected information while intending an economic benefit for someone besides Google. They also needed to establish the required injury to the owner.
The evidence about startups, outside roles, fundraising, and technical plans fit that theory more directly. Prosecutors said Ding discussed becoming chief technology officer at one company shortly after his uploading began.
They also said he founded Shanghai Zhisuan Technology and acted as its chief executive. The startup proposed software for accelerating machine-learning workloads on supercomputing chips. Ding reportedly told potential investors he could build an AI supercomputer by copying and modifying Google technology.
A planned commercial advantage for those businesses could support trade-secret theft without proving a Chinese government benefit. That is why both sets of charges could cover the same documents yet produce different outcomes after judicial review.
The reversal is therefore not a contradiction. It is an example of criminal statutes placing different boundaries around related conduct. The jury found the broader factual story persuasive, while the judge found one required legal element unsupported.
That distinction will matter in future cases. Prosecutors can present foreign affiliations, state industrial policies, and strategic technology goals. Courts will still ask whether the evidence proves the defendant intended the precise foreign-government benefit required by law.
Google and Other AI Labs Face an Insider-Security Test
The ruling weakens one prosecution theory, but it does not reduce the operational risk facing companies that build AI infrastructure.
Google’s secrets covered several layers of its computing stack. An employee working in one layer could access information with value across chips, networks, scheduling software, and data-center operations. That concentration makes access useful for development and dangerous during misuse.
AI laboratories face the same organizational tension. Engineers need enough information to diagnose failures across complex systems. Excessive compartmentalization slows collaboration, yet broad access can increase the impact of a compromised or disloyal account.
The alleged copying method shows why conventional perimeter defenses are insufficient. Authentication can confirm that an authorized engineer opened a document. It cannot determine by itself whether the engineer plans to use that information for assigned work.
Security controls must therefore examine behavior and context. Unusual document volume, conversion into portable formats, personal cloud uploads, and undeclared outside employment can become meaningful when evaluated together.
Each signal also has an innocent explanation. Engineers routinely move between tools, create notes, and work across many files. Monitoring without clear rules can invade privacy, generate false alerts, or discourage legitimate research.
That creates a tradeoff between protecting intellectual property and preserving a workable engineering culture. Companies need precise controls, documented escalation paths, and reviews that distinguish unusual behavior from ordinary experimentation.
Google said after the initial charges that it had strict safeguards for confidential information. The company also said it found numerous stolen documents and referred the matter to law enforcement. Its response shows the value of an internal investigation, but the timeline highlights limits in prevention.
The company reportedly discovered the uploads after learning about Ding’s outside presentation. That suggests business-context information helped security teams interpret technical logs. Neither human reporting nor automated monitoring was sufficient alone.
Other AI developers face comparable exposure. OpenAI, Anthropic, Microsoft, Amazon, Meta, and specialized chip companies all rely on employees who understand valuable system details. Those details can include model designs, training techniques, accelerator layouts, and deployment procedures.
The case does not establish that every AI company faces the same controls or weaknesses. It does show how portable knowledge spans organizational boundaries. An employee can carry expertise legitimately, while taking protected documents remains illegal.
That boundary is difficult to enforce because trade secrets are not the same as patents. Patents disclose an invention in exchange for limited exclusive rights. Trade secrets retain protection through secrecy and reasonable defensive measures.
Companies must identify which material deserves that treatment. Labeling everything confidential can weaken employee understanding and complicate enforcement. Focused classification gives teams a clearer basis for access limits and incident response.
Technical controls should follow that classification. High-value architecture documents can receive narrower permissions, stronger logging, and restrictions on exports. Alerts can combine document sensitivity with volume, destination, timing, and employment context.
Process controls matter just as much. Employees need clear disclosure rules for outside work, startup involvement, and conflicts of interest. Departing workers should complete targeted reviews based on actual access, not only sign broad deletion statements.
The case also supports closer coordination among human resources, legal, and security teams. A foreign trip alone proves nothing improper. A trip combined with hidden executive work, unusual downloads, and misleading access records creates a different risk picture.
Companies must avoid turning national origin into a security signal. Ding’s Chinese citizenship was part of the public case, but citizenship does not predict misconduct. Controls should focus on behavior, access, conflicts, and verified affiliations.
That principle becomes especially important after the partial acquittal. Chhabria’s ruling rejects a shortcut between China-related commercial activity and benefit to China’s government. Corporate security programs should avoid a comparable shortcut in employee monitoring.
The right lesson is narrower and more useful. Protect critical information according to its value, observe high-risk transfers, enforce conflict rules consistently, and investigate combined signals. Those steps address insider risk without treating identity as evidence.
Why the Partial Acquittal Matters Beyond Google
The decision raises the evidentiary bar for labeling AI theft as state-directed economic espionage.
The Justice Department has treated sensitive technologies as both economic assets and national security resources. AI infrastructure sits near the center of that policy because advanced computing supports commercial models, scientific work, surveillance, and military applications.
January’s verdict appeared to validate an expansive enforcement narrative. Officials described Ding’s conduct as a betrayal of Google and the United States. They framed the prosecution around competition with China for AI leadership.
The partial acquittal does not reject concern about foreign technology acquisition. It requires the government to support its strongest accusation with evidence tied to statutory elements. Policy urgency cannot lower the criminal burden of proof.
That constraint benefits the credibility of enforcement. Economic espionage should mean more than valuable information crossing into a strategic competitor’s market. If the label becomes automatic, it can obscure differences among personal enrichment, corporate theft, and state-directed operations.
Those categories can overlap. A founder may seek personal wealth while advancing a private company and supporting government priorities. Criminal law still asks which relationships and intentions prosecutors proved, not which geopolitical narrative seems plausible.
The distinction also affects public understanding. Headlines about “stealing for China” can merge a country, its government, its companies, and its citizens into one actor. Chhabria’s ruling shows why courts require more precision.
For defense lawyers, the decision provides a clear path for challenging future Section 1831 charges. They can demand evidence that connects the intended benefit to a government or covered entity. General industrial policy or national advantage may not be sufficient.
For prosecutors, the lesson concerns case construction. Evidence might include direction from officials, government control of a beneficiary, specific procurement plans, funding arrangements, or communications showing an intended state benefit.
Not every case will contain such evidence. When it does not, prosecutors can still use trade-secret theft laws if the underlying facts satisfy them. Ding’s seven remaining convictions demonstrate that alternative.
The ruling may also influence charging decisions. Adding economic espionage counts raises maximum penalties and gives a case national security significance. It also creates an element that can fail even when theft is well documented.
That does not mean prosecutors will stop bringing such charges. Advanced technology remains a government priority, and the Justice Department has specialized counterintelligence resources. Future indictments will likely describe the foreign-state connection with greater care.
The defense still has reasons to challenge the remaining verdict. Ding previously sought acquittal or a new trial on multiple grounds. Chhabria rejected those broader arguments in June before later removing the economic espionage counts.
One dispute concerned “combination trade secrets,” meaning protected information created by combining material from several documents. The court accepted that a protected combination need not be stored by the owner as one assembled package.
That issue matters for modern AI systems. Their competitive value often comes from relationships among components, not one isolated file. Architecture, performance data, scheduling logic, and network design can reveal more together than separately.
Companies should not treat the ruling as a reason to relax protections. The court preserved convictions involving all seven trade-secret categories. That result reinforces the potential criminal consequences of taking confidential AI infrastructure information.
The government should not treat the remaining convictions as proof of state direction. Its strongest public framing no longer matches the judgment. An appeal may revisit that conclusion, but current reporting should preserve the distinction.
For readers following google news, that is the core reversal. The government still has a serious AI theft conviction. It no longer has the economic espionage precedent that officials celebrated in January.
Three Signals to Watch Next
The next stage will show whether this case becomes a narrow trial-court correction or a broader guide for AI espionage prosecutions.
The first signal is any government appeal. Prosecutors can ask a higher court to review Chhabria’s conclusion about evidentiary sufficiency. An appeal would test how directly Section 1831 requires defendants to connect their conduct with a foreign state.
A successful appeal would restore the seven economic espionage convictions and revive the Justice Department’s claimed precedent. An unsuccessful appeal would strengthen the ruling’s value for defendants facing similar theories.
The government’s choice not to appeal would also matter. It could indicate acceptance that the trial evidence did not establish the required connection. It would not necessarily signal a change in wider enforcement policy.
The second signal is the treatment of the seven surviving convictions at sentencing. The court must calculate a sentence under federal statutes and guidelines, then consider the particular circumstances. Statutory maximums alone reveal little about the likely result.
Sentencing arguments can show how both sides characterize the harm. Prosecutors may emphasize the sensitivity, scale, concealment, and competitive value of the information. The defense may stress the dismissed espionage counts and dispute broader national security claims.
The judge’s final explanation will be especially informative. It can clarify whether the surviving conduct is treated chiefly as commercial theft, a serious security breach, or conduct carrying wider strategic consequences.
The third signal is the next AI-related economic espionage indictment. Prosecutors now have a public example of a foreign-government theory failing after trial. Future charging documents should reveal how they respond.
Look for more specific allegations about state control, official direction, public financing, procurement, or communications with government representatives. Those facts would strengthen a claim beyond general alignment with national technology policies.
Companies should watch those cases without waiting for courts to settle every legal boundary. The operational threat exists before prosecutors choose between trade-secret theft and economic espionage. Sensitive AI information can create real competitive harm under either label.
Security leaders should review whether their controls can identify large movements of confidential content into personal applications or storage. They should also test whether outside-business disclosures reach the teams responsible for technical risk.
Employees and founders should understand the boundary just as clearly. General knowledge and professional experience can travel with a worker. Confidential documents, protected combinations, and internal system details cannot simply become startup assets.
Readers should also resist the easiest interpretation of the result. Ding did not defeat the entire prosecution, and Google’s theft case did not collapse. A judge removed seven counts because one element lacked sufficient proof.
That precision is worth carrying into future google news coverage. AI competition encourages sweeping stories about nations, companies, and strategic advantage. Criminal judgments turn on narrower questions about documents, conduct, knowledge, and intent.
The case’s next filings will determine whether the national security theory returns. Until then, the judgment contains two conclusions at once. Google proved its AI trade secrets were criminally stolen, while prosecutors failed to prove the theft was intended to benefit China’s government.
That split is not a minor procedural detail. It is the line between an insider-theft conviction and a landmark economic espionage precedent. Watch the appeal decision, sentencing record, and next government indictment to see where that line moves.


