Former Google Engineer Sentenced for Stealing AI Trade Secrets
Linwei Ding received nearly a year in prison for systematically uploading confidential files on Google's AI infrastructure to a personal cloud account.
A former Google software engineer will serve nearly a year in prison for stealing trade secrets related to the company's artificial intelligence infrastructure, a federal judge ruled Tuesday in San Francisco.
U.S. District Judge Vince Chhabria sentenced Linwei Ding, 38, calling his actions a "systematic, brazen effort to steal Google's property." The judge said Ding "knew very well what he was doing" and "hurt people along the way."
Ding was convicted in January on seven counts of theft of proprietary information following a jury trial. Prosecutors had also secured an economic espionage conviction, alleging Ding intended to benefit China, but Judge Chhabria vacated that count in August, finding insufficient evidence to support it.
The theft operation
According to trial evidence, Ding uploaded more than 500 confidential files from Google's network to a personal Google Cloud account over the course of a year. The stolen information included trade secrets related to Google's hardware infrastructure and software for supercomputing data centers used to train large AI models.
Ding joined Google as a software engineer in 2019 after working at multiple Silicon Valley technology companies. He became a lawful permanent U.S. resident in 2021.
Months after beginning the uploads, Ding accepted a Chief Technology Officer position at Rongshu, an early-stage technology company in China, and visited the company in late 2022. In 2023, he founded his own China-based company, Zhisuan, focused on training large AI models.
A November 2023 Zhisuan document circulated by Ding stated: "We have experience with Google's ten-thousand-card computational power platform; we just need to replicate and upgrade it and then further develop a computational power platform suited to China's national conditions."
Ding never disclosed either company affiliation to Google. Prosecutors said he had an intern swipe his Google identification card multiple times while he was in China pitching Zhisuan "to make it appear as though he was working from his office."
Why it matters
The case highlights the persistent threat of intellectual property theft in AI development, where infrastructure and training methodologies represent years of research and billions in investment. As the U.S. and China compete for AI dominance, the theft of proprietary information about large-scale computing systems gives competitors a significant advantage without the cost of independent development. The sentence sends a signal about consequences for trade secret theft, even as the judge found the espionage charges unsupported—a distinction that may influence how similar cases are prosecuted.
Sentencing and aftermath
Ding's defense attorneys had requested three months of home confinement, arguing he had already been punished through professional ruin and should remain available as his eight-year-old son's primary caregiver. They noted that "Mr. Ding will never again hold a position of trust at a technology company" and that Zhisuan is now defunct.
Judge Chhabria rejected the request for a non-custodial sentence, saying it failed to reflect the seriousness of the offense or provide adequate deterrence. In addition to the prison term, Ding must pay more than $189,000 in restitution, a $25,000 fine, and will face two years of supervised release.
Details of the case were first reported by KQED.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call