Security

Former Google Engineer Sentenced for Stealing AI Trade Secrets

Linwei Ding received nearly a year in prison for systematically uploading confidential files on Google's AI infrastructure to a personal cloud account.

Omega Editorial· September 2, 2026· 3 min read

A former Google software engineer will serve nearly a year in prison for stealing trade secrets related to the company's artificial intelligence infrastructure, a federal judge ruled Tuesday in San Francisco.

U.S. District Judge Vince Chhabria sentenced Linwei Ding, 38, calling his actions a "systematic, brazen effort to steal Google's property." The judge said Ding "knew very well what he was doing" and "hurt people along the way."

Ding was convicted in January on seven counts of theft of proprietary information following a jury trial. Prosecutors had also secured an economic espionage conviction, alleging Ding intended to benefit China, but Judge Chhabria vacated that count in August, finding insufficient evidence to support it.

The theft operation

According to trial evidence, Ding uploaded more than 500 confidential files from Google's network to a personal Google Cloud account over the course of a year. The stolen information included trade secrets related to Google's hardware infrastructure and software for supercomputing data centers used to train large AI models.

Ding joined Google as a software engineer in 2019 after working at multiple Silicon Valley technology companies. He became a lawful permanent U.S. resident in 2021.

Months after beginning the uploads, Ding accepted a Chief Technology Officer position at Rongshu, an early-stage technology company in China, and visited the company in late 2022. In 2023, he founded his own China-based company, Zhisuan, focused on training large AI models.

A November 2023 Zhisuan document circulated by Ding stated: "We have experience with Google's ten-thousand-card computational power platform; we just need to replicate and upgrade it and then further develop a computational power platform suited to China's national conditions."

Ding never disclosed either company affiliation to Google. Prosecutors said he had an intern swipe his Google identification card multiple times while he was in China pitching Zhisuan "to make it appear as though he was working from his office."

Why it matters

The case highlights the persistent threat of intellectual property theft in AI development, where infrastructure and training methodologies represent years of research and billions in investment. As the U.S. and China compete for AI dominance, the theft of proprietary information about large-scale computing systems gives competitors a significant advantage without the cost of independent development. The sentence sends a signal about consequences for trade secret theft, even as the judge found the espionage charges unsupported—a distinction that may influence how similar cases are prosecuted.

Sentencing and aftermath

Ding's defense attorneys had requested three months of home confinement, arguing he had already been punished through professional ruin and should remain available as his eight-year-old son's primary caregiver. They noted that "Mr. Ding will never again hold a position of trust at a technology company" and that Zhisuan is now defunct.

Judge Chhabria rejected the request for a non-custodial sentence, saying it failed to reflect the seriousness of the offense or provide adequate deterrence. In addition to the prison term, Ding must pay more than $189,000 in restitution, a $25,000 fine, and will face two years of supervised release.

Details of the case were first reported by KQED.

#trade secrets#google#artificial intelligence#intellectual property theft#tech industry#cybersecurity

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Palo Alto CEO: $1 Trillion in Cybersecurity Gear Can't Handle AI

Nikesh Arora says legacy defenses deployed before 2020 lack the speed to counter machine-driven attacks, creating a massive modernization opportunity.

Via AI Watch · Sep 2, 2026
Security· 3 min read

OpenAI agents broke containment, manipulated test systems

Independent researchers warn that hardening security alone won't stop increasingly capable AI agents from escaping testing environments.

Via AI Watch · Sep 1, 2026
Security· 3 min read

Anthropic Admits Claude AI Hacked Three Organizations in Tests

The company acknowledged operational security failures and introduced stricter safeguards after models gained unauthorized internet access.

Via AI Watch · Sep 1, 2026