On January 29, 2026, after an 11-day trial, a federal jury in San Francisco returned its verdict: Linwei Ding, also known as Leon Ding, a 38-year-old former Google software engineer and Chinese national, was found guilty on all counts — seven of economic espionage and seven of theft of trade secrets. The Justice Department announced the conviction the next day, and FBI Assistant Director Roman Rozhavsky framed it as marking “the first-ever conviction on AI-related economic espionage charges.” The core allegation: during his time at Google, Ding copied more than 2,000 pages of confidential material covering the hardware and software Google uses to train and serve large AI models in its supercomputing data centers, intending to benefit two China-based companies.
The significance for the AI industry is a newly drawn enforcement line. What was stolen was not model weights but the infrastructure technology that makes frontier training possible — and the US government has now shown it will deploy its heaviest trade-secret weapon, economic espionage charges carrying up to 15 years per count, to protect that layer.
The Facts: 2,000-Plus Pages and Two Chinese Companies
Per the DOJ press release, the timeline runs roughly as follows:
- May 2022 to April 2023: while employed at Google, Ding copied over 2,000 pages of confidential material from Google’s network and uploaded it to his personal Google Cloud account
- Around June 2022: began discussing a CTO role at an early-stage Chinese company; by early 2023 he had founded his own China-based AI/machine-learning company and served as its CEO
- His pitch to investors: he could build an AI supercomputer by copying and modifying Google’s technology
- December 2023: transferred the files to his own computer less than two weeks before resigning; that same quarter he applied to a Shanghai government “talent program,” writing that he would “help China to have computing power infrastructure capabilities that are on par with” global standards
- Indicted in March 2024, superseded in February 2025 into 14 counts; convicted January 29, 2026, with a status conference set for February 3 and sentencing still pending
What Was Stolen: TPUs, SmartNICs, and Cluster Orchestration Software
The DOJ’s list of secrets falls into seven categories, all pointing the same direction: the architecture and functionality of Google’s custom Tensor Processing Unit (TPU) chips and systems, GPU systems, the software that lets chips communicate and execute tasks, the software that orchestrates thousands of chips into a single supercomputer for AI workloads, and Google’s custom-designed SmartNIC for high-speed communication.
In other words, the engineering knowledge of how to assemble thousands of chips into a machine that can train large models. This class of technology is worth no less than model weights — weights are the product, this is the production capacity. For any organization wanting to replicate frontier training capability, these documents skip years of infrastructure trial and error.
Why the “First” AI Espionage Conviction Matters
Both the FBI and the Foundation for Defense of Democracies frame the case as the first successful prosecution of Chinese AI-related economic espionage. Two things follow. First, prosecutors took 18 U.S.C. § 1831 economic espionage charges to an AI technology theft case and won a jury verdict, establishing a prosecution template for future cases. Second, enforcement focus has officially extended from traditional semiconductors to the AI supercomputing stack. John A. Eisenberg of the Justice Department’s National Security Division said it plainly: “Ding abused his privileged access to steal AI trade secrets while pursuing PRC government-aligned ventures.”
Insider-Threat Lessons for AI Teams
Three directly actionable conclusions. First, access design: a single engineer could reach secrets spanning chips, network cards, and cluster orchestration, which means the access boundary around “infrastructure-class secrets” was far too wide — least privilege needs to be enforced on these assets more strictly than on model weights. Second, the exfiltration path was unglamorous: copying to a personal cloud account was enough, so DLP has to cover the most mundane route of all, internal network to personal SaaS. Third, the behavioral signals existed: an outside CTO negotiation, a foreign startup, a government talent-program application — all became part of the evidentiary chain. Conflict-of-interest disclosures are not compliance paperwork; they are early-warning data.
Sources
- Former Google Engineer Found Guilty of Economic Espionage and Theft of Confidential AI Technology — U.S. Department of Justice
- Justice Department Marks First Successful Prosecution of Chinese AI-Related Economic Espionage — FDD
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
