Ex-Google Engineer Linwei Ding Sentenced to Nearly One Year for Stealing AI Trade Secrets
Key Takeaways
- •Ding stole thousands of pages of Google AI trade secrets between May 2022 and April 2023, covering TPU chips, GPU systems, SmartNIC networking, and orchestration software.
- •He was sentenced to 12 months minus one day in prison, two years of supervised release, more than $198,000 in restitution, and a $2,500 fine, exceeding the sentencing guideline range.
- •Judge Chhabria vacated seven economic espionage convictions for lack of evidence of intent to benefit the Chinese government, while the seven trade-secret theft convictions stood.
- •Prosecutors had sought a 70-month term, while the defense requested three months of home confinement; the judge rejected a noncustodial sentence.
- •Ding must surrender within 90 days after his request to remain free pending appeal was denied.

Former Google software engineer Linwei Ding was sentenced on September 1 to nearly one year in federal prison for stealing confidential technology used to build and operate the company's artificial intelligence supercomputers. The case is one of the most prominent trade-secret prosecutions to date targeting the specialized chip and infrastructure technology underpinning large-scale AI training, and it comes as U.S. authorities have increasingly prioritized cases involving the theft of AI-related intellectual property.
U.S. District Judge Vince Chhabria imposed a term of 12 months minus one day, followed by two years of supervised release. Ding was also ordered to pay more than $198,000 in restitution to Google and a $2,500 fine. The sentence exceeded the federal guideline range of zero to six months. Chhabria described Ding's conduct as a "systematic, brazen effort" involving thousands of pages of internal Google material and denied his request to remain free while appealing.
Ding Took Google TPU and GPU Technology
Ding joined Google in 2019 and began transferring confidential material to a personal cloud account in May 2022. Between May 2022 and April 2023, he stole thousands of pages of AI trade secrets covering hardware and software used inside Google's supercomputing data centers.
The stolen material included the architecture and functionality of Google's Tensor Processing Unit (TPU) chips, GPU systems, high-speed SmartNIC networking technology, and the software used to coordinate thousands of chips into infrastructure capable of training and running large AI models. TPUs are custom accelerators Google developed in-house to train and serve its AI models, making details of their design and the surrounding software stack among the company's most closely guarded competitive assets in the AI race.
According to the case record, Ding copied information from Google source files into Apple Notes on his company laptop, converted the material into PDFs, and uploaded it to personal storage. He later downloaded the stolen material onto his own computer shortly before leaving Google.
The case follows another internal-data prosecution involving a Google engineer and crypto markets. Michele Spagnuolo was charged in May over a $1.2 million Polymarket scheme after allegedly accessing confidential Google search-trend data and using it to trade prediction-market contracts before the information became public.
Chinese AI Ventures Were Developed During Google Employment
While still employed at Google, Ding became involved with an early-stage Chinese technology company and later developed his own China-based AI startup. Investor materials for the startup claimed it could build an AI supercomputer by copying and modifying Google technology.
A federal jury initially convicted Ding in January on seven counts of theft of trade secrets and seven counts of economic espionage. The trade-secret convictions survived post-trial challenges. However, Chhabria vacated all seven economic espionage counts on August 20, finding insufficient evidence that Ding intended or knew his theft would benefit the Chinese government — a separate element required under the economic espionage statute. The ruling left intact the finding that Ding intended to benefit himself and his emerging Chinese AI company through the stolen technology.
Prosecutors Sought a Much Longer Prison Term
Federal prosecutors sought a 70-month prison sentence, while Ding's defense requested three months of home confinement. Chhabria rejected a noncustodial sentence, finding that the guideline range did not adequately reflect the seriousness of the theft. The substantial gap between the prosecutors' request and the final term underscores how sentencing guidelines, written before AI infrastructure theft emerged as a distinct category of economic harm, can diverge sharply from the government's view of such cases.
Ding also sought to delay imprisonment pending his appeal, but the request was denied. He must surrender to begin his 12-month-minus-one-day prison term within 90 days. His appeal will be a further test of how courts handle trade-secret theft in the AI sector, where stolen designs and software can be far harder to value than traditional physical IP.