Linwei Ding AI Theft Conviction Overturned in Part by Judge 2026

Table of Contents
Linwei Ding, a former Google software engineer, secured a major legal victory on Thursday after a federal judge threw out the economic espionage portion of his conviction, citing insufficient evidence of foreign state involvement. U.S. District Court Judge Vince Chhabria in San Francisco ruled that federal prosecutors failed to prove that the Chinese national, also known as Leon Ding, intended or knew his actions would benefit the government of China. This lack of proof invalidated seven counts of economic espionage. However, Judge Chhabria upheld the other seven counts of theft of trade secrets, confirming that the evidence supported the jury’s finding that Ding had stolen proprietary artificial intelligence blueprints from his former employer.
The decision brings a dramatic twist to what was widely regarded as a landmark case in Silicon Valley. Indicted in March 2024, with charges subsequently expanded in a February 2025 superseding indictment, Ding was found guilty on all fourteen counts following an 11-day trial in January 2026. The case was heralded by federal law enforcement as the first-ever conviction on AI-related economic espionage, highlighting the intense scrutiny of cross-border technological transfers. While the ruling removes the threat of decades of imprisonment associated with the economic espionage charges—which carry up to 15 years per count—Ding still faces substantial prison time on the remaining theft charges as he approaches his scheduled sentencing on September 1, 2026.
Table of Contents
- The Judicial Ruling by Judge Vince Chhabria
- Details of the Google AI Trade Secret Theft
- The Legal Threshold for Economic Espionage
- Section 1831 vs Section 1832: Theft vs Espionage
- Links to Chinese Tech Startups and Financial Benefits
- Implications for Silicon Valley Intellectual Property
- Summary of Charges, Evidentiary Standards, and Rulings
- Broader Geopolitical Context and National Security
- What Lies Ahead for the Prosecution and Defense
The Judicial Ruling by Judge Vince Chhabria
In a detailed ruling delivered in San Francisco, Judge Vince Chhabria addressed the defense’s motion for acquittal, which was filed three weeks after the January trial. The defense argued that the Department of Justice had failed to present sufficient evidence to prove beyond a reasonable doubt that Ding’s conduct met the rigorous statutory definitions required under the Economic Espionage Act. Specifically, they targeted the accusation that Ding was acting on behalf of, or with the intent to benefit, a foreign government.
Judge Chhabria agreed with the defense regarding the espionage counts, asserting that the prosecution’s case relied on a series of assumptions rather than concrete evidence of state-sponsored intent. Under U.S. law, to convict an individual of economic espionage, prosecutors must establish that the defendant intended or knew that their offense would benefit a foreign government, foreign instrumentality, or foreign agent. The judge found that while Ding undoubtedly sought to benefit himself and early-stage Chinese startups, the link to the Chinese government itself was too tenuous to support a criminal conviction on those specific charges.
Conversely, Chhabria made it clear that the evidence supporting the trade secret theft counts was overwhelming. The court affirmed that the government successfully demonstrated Ding’s unauthorized copying, downloading, and conversion of Google’s proprietary AI technology for commercial gain. Consequently, while the espionage convictions have been overturned, the core of the theft conviction remains entirely intact, leaving Ding facing serious legal consequences.
Details of the Google AI Trade Secret Theft
The underlying theft occurred over a multi-year period, beginning roughly three years after Ding joined Google as a software engineer in May 2019. According to court records, Ding began systematically copying thousands of pages of highly confidential information in May 2022. This stolen repository included details of the hardware infrastructure and software platforms that power Google’s supercomputing data centers—the physical and digital backbones used to train large-scale artificial intelligence models.
Among the stolen materials were blueprints for specialized computer chips, specifically Google’s Tensor Processing Units (TPUs). Google developed these proprietary chips to give itself a competitive edge over industry rivals such as Amazon Web Services and Microsoft, which also design their own silicon. Additionally, these custom TPUs were designed to reduce Google’s reliance on high-end graphic processing units manufactured by Nvidia. By copying the architecture of these supercomputing systems, Ding obtained the blueprints for the exact systems driving the modern AI revolution. This high-stakes race for computational dominance reflects the industry-wide push for proprietary neural network architectures, a contrast to the Zuckerberg manifesto on open source AI that advocates for collaborative ecosystem development.
The sophisticated software platforms Ding stole allowed Google to efficiently coordinate thousands of TPUs, facilitating the complex mathematical computations required to train large language models. The stolen code was not merely conceptual; it represented operational instructions on how to scale AI training to levels capable of rivaling the latest OpenAI advancements in generative artificial intelligence. By placing these details in his personal Google Drive, Ding essentially took the recipe for Google’s proprietary AI supercomputer.
The Legal Threshold for Economic Espionage
The partial dismissal of Ding’s conviction highlights the complex statutory distinctions in federal intellectual property law. The Economic Espionage Act of 1996 outlines two distinct offenses: economic espionage under 18 U.S.C. § 1831, and theft of trade secrets under 18 U.S.C. § 1832. Understanding the boundaries between these two statutes is critical to understanding why Judge Chhabria divided the jury’s verdict.
To secure a conviction under Section 1831 (Economic Espionage), the government must prove that the defendant stole a trade secret with the intent or knowledge that the offense would “benefit any foreign government, foreign instrumentality, or foreign agent.” This is an incredibly high evidentiary hurdle. It is not enough to show that a defendant’s actions benefited a foreign corporation or a foreign national; there must be a direct, demonstrable link to a foreign state apparatus. In Ding’s case, while the foreign companies he aligned with were based in China, the court found a lack of proof that these companies were acting as conduits or instrumentalities of the Chinese state, or that Ding intended for state actors to benefit from his theft.
Section 1831 vs Section 1832: Theft vs Espionage
In contrast, Section 1832 (Theft of Trade Secrets) does not require any foreign state connection. To convict under this section, the prosecution only needs to prove that the defendant stole, duplicated, or possessed a trade secret with the intent to convert it to the economic benefit of anyone other than the owner, and with the intent to injure the owner. Because the evidence clearly showed Ding designed to use Google’s tech to advance his own commercial ventures and those of his startup partners, the criteria for Section 1832 were met. This distinction underscores the importance of rigorous prosecutorial evidence when attempting to escalate commercial theft cases into national security trials.
Links to Chinese Tech Startups and Financial Benefits
The prosecution’s case detailed how Ding was courted by Chinese technology companies while still employed at Google’s offices in California. In 2022, Ding was offered a position as Chief Technology Officer (CTO) for Rongshu, an early-stage Chinese technology startup specializing in machine learning and AI applications. Court documents showed that Ding traveled to China, participated in investor meetings, and was offered equity in the company in exchange for his technical expertise.
Furthermore, by late 2023, Ding had founded his own China-based startup, Shanghai ZhiSuan Technology, where he served as Chief Executive Officer. ZhiSuan focused on accelerating AI training models and optimizing supercomputing clusters. Prosecutors argued that Ding’s startup actively pitched itself to Chinese venture capitalists by boasting of its access to cutting-edge power and infrastructure platforms—the very systems Ding was actively duplicating from Google’s internal servers. Ding’s activities were not merely speculative; they were part of a commercial blueprint to capitalize on stolen proprietary corporate code to achieve rapid market valuation in China’s booming AI sector.
Implications for Silicon Valley Intellectual Property
The Ding case has sent shockwaves through Silicon Valley, forcing many technology firms to re-evaluate their internal security architectures. For years, tech giants have operated on a culture of trust and open internal collaboration, allowing engineers broad access to codebases to encourage innovation. However, as AI models have become national security assets and multi-billion-dollar commercial drivers, this open-access model has come under severe strain.
The methods Ding used to exfiltrate data have prompted Google and its peers to implement far more stringent corporate intellectual property safeguards. According to trial testimony, Ding copied data from Google’s network into his personal Google Drive by utilizing intermediary software and converting documents to avoid automated security triggers. To hide his physical absence while working in China, Ding even had an associate badge-in at his San Francisco office. This level of deception has highlighted key vulnerabilities in standard corporate monitoring, forcing companies to implement zero-trust architectures and behavioral analytics to detect anomalous file transfers and logins.
Summary of Charges, Evidentiary Standards, and Rulings
To clarify the legal landscape following Judge Chhabria’s decision, the table below outlines the differences between the two categories of charges Ding faced, the associated penalties, and the court’s ultimate ruling on each.
| Charge Type | US Code Citation | Key Evidentiary Requirement | Max Penalty per Count | Judge Chhabria’s Ruling |
|---|---|---|---|---|
| Economic Espionage (7 Counts) | 18 U.S.C. § 1831 | Intent to benefit a foreign government, instrumentality, or agent. | 15 Years Prison / $5M Fine | Tossed / Overturned due to insufficient evidence of state intent. |
| Theft of Trade Secrets (7 Counts) | 18 U.S.C. § 1832 | Intent to convert trade secret for commercial benefit of another; intent to injure owner. | 10 Years Prison / $250k Fine | Upheld / Sustained; evidence of commercial theft was overwhelming. |
Broader Geopolitical Context and National Security
The prosecution of Linwei Ding did not occur in a vacuum; it is part of a broader, concerted campaign by the United States government to protect domestic technological supremacy, particularly in artificial intelligence. The Department of Justice, in partnership with the FBI and the Department of Commerce, established the “Disruptive Technology Strike Force” specifically to target the illicit transfer of critical technologies to foreign adversaries like China, Russia, and Iran. This initiative is closely tied to evolving Department of Defense technology policies that classify advanced generative AI and GPU supercomputing structures as dual-use technologies with massive military implications.
As governments globally view AI as a strategic geopolitical frontier, the enforcement of national security-related technology transfer laws has become highly politicized. This case reflects how domestic legal frameworks are being pushed to their limits to address global economic espionage. While the U.S. government maintains that these prosecutions protect domestic industries, they also contribute to rising geopolitical tensions over US policies regarding international trade and security. Consequently, managing tech exports has forced regulators to frequently update international trade laws and import licenses to curb the flow of advanced microchips and software platforms to Chinese firms.
Furthermore, independent industry analysts have highlighted that the pressure to acquire advanced Western technology drives both state-sponsored and corporate espionage. The rapid advancement of Silicon Valley’s AI ecosystems acts as a magnet for foreign companies seeking to leapfrog developmental cycles. There have been several warning signs in the global tech ecosystem indicating that intellectual property exfiltration is becoming highly decentralized, occurring via individual employees and startup founders rather than traditional state intelligence officers, which makes legal prosecution under espionage statutes highly complex.
What Lies Ahead for the Prosecution and Defense
Despite the dismissal of the seven economic espionage charges, Ding remains in a precarious legal position. With the seven counts of trade secret theft upheld, the former Google software engineer still faces a maximum theoretical sentence of up to 70 years in prison (10 years per count) and millions of dollars in potential fines. In practice, federal sentencing guidelines rarely impose maximum consecutive sentences for first-time non-violent offenders, but the scale of the theft and the value of the intellectual property exfiltrated from Google will heavily weigh on the judge’s final decision.
The Justice Department has not yet announced whether it intends to appeal Judge Chhabria’s ruling regarding the economic espionage charges to the Ninth Circuit Court of Appeals. Prosecutors may decide to proceed directly to sentencing on the trade secret theft charges to secure a swift and substantial prison term, rather than engaging in a protracted appellate process over the state-benefit requirements. Ding’s defense attorney expressed gratification with the ruling, stating that the court correctly identified the lack of connection between Ding’s private entrepreneurial activities and the government of China. All eyes now turn to the San Francisco federal courthouse on September 1, 2026, where Judge Chhabria will determine the final sentence for Leon Ding, concluding one of the most high-profile technology theft cases in modern Silicon Valley history.



