Federal prosecutors in California have formally requested that a judge sentence former Google software engineer Linwei Ding to a prison term exceeding five years, marking a significant milestone in one of the most high-profile cases involving the theft of artificial intelligence trade secrets. The sentencing memorandum, filed in a federal court in the Northern District of California, underscores the gravity of the theft, which involved the systematic extraction of proprietary information related to Google’s advanced AI data center hardware and software.
While the government is pushing for a 63-month sentence, defense attorneys for Ding, also known as Leon Ding, have countered with a request for home confinement. The defense argues that the government’s sentencing recommendation is based on "speculative evidence" regarding the actual economic loss and notes that Ding was acquitted of more severe economic espionage charges. This legal battle highlights the intensifying friction between corporate security, international technological competition, and the judicial system’s efforts to quantify the value of intangible intellectual property.
The Magnitude of the Theft: AI Trade Secrets at Stake
The case against Linwei Ding centers on the theft of more than 500 confidential files from Google’s internal network. According to court documents, these files contained highly sensitive information regarding Google’s proprietary artificial intelligence infrastructure. Specifically, the data focused on the company’s Tensor Processing Units (TPUs)—custom-designed chips that power some of the world’s most advanced AI workloads, including the training and deployment of large language models.
The stolen information included detailed specifications for TPU v4 and TPU v6, as well as the software orchestration layers that allow thousands of these chips to work in unison. Prosecutors emphasize that Google spent years and hundreds of millions of dollars developing this technology to gain a competitive edge in the rapidly evolving AI sector. By transferring this data to his personal accounts, Ding allegedly sought to bypass years of research and development for his own benefit and for the benefit of entities based in the People’s Republic of China (PRC).
Federal officials have characterized the theft as a "betrayal of trust" that strikes at the heart of American innovation. The Department of Justice (DOJ) argues that a significant prison sentence is necessary to deter other high-tech employees from attempting similar thefts, particularly as the global race for AI supremacy accelerates.
A Double Life: From Google Engineer to Startup CTO
The investigation into Ding revealed a complex narrative of dual employment and clandestine entrepreneurship. Ding joined Google in 2019 as a software engineer, a role that granted him access to the company’s most guarded secrets regarding its data center architecture. However, prosecutors allege that as early as 2022, Ding began a secret life that directly conflicted with his duties at the tech giant.
According to the indictment, Ding was offered the position of Chief Technology Officer (CTO) at an early-stage technology company based in China, Beijing Jiushinao Technology Co. He reportedly traveled to China to participate in investor meetings and was offered a significant equity stake in the firm. Furthermore, Ding allegedly founded his own startup, Shanghai Zhisuan Technology Co., which focused on accelerating AI training through specialized software—a direct application of the knowledge he was purportedly stealing from Google.
To facilitate the theft without detection, Ding allegedly copied data from Google source files into the Apple Notes application on his Google-issued laptop. He then converted those notes into PDFs and uploaded them to his personal Google Cloud account. This method was designed to circumvent data loss prevention (DLP) systems that monitor for the direct transfer of large source code files or sensitive documents to external drives or cloud services.
Timeline: The Evolution of a Corporate Espionage Case
The trajectory of the Ding case offers a clear view of how internal security threats can remain undetected for extended periods before surfacing.
- 2019: Linwei Ding is hired by Google as a software engineer, working on the development of AI data center software.
- May 2022: Ding begins secretly uploading confidential Google files to his personal cloud account. This activity continues for approximately one year.
- June 2022: Ding is reportedly approached by a Chinese startup and begins discussions regarding a CTO role while still employed at Google.
- Late 2022 – Early 2023: Ding spends significant time in China, attending meetings for his startup ventures, while his colleagues at Google believe he is working remotely or is on leave.
- December 2023: Google’s internal security team detects suspicious data transfers. Ding resigns from the company shortly thereafter.
- January 2024: Google discovers the full extent of the data breach and alerts federal authorities.
- March 2024: Ding is arrested and indicted on four counts of theft of trade secrets.
- August 2024: Following a legal process that saw Ding acquitted of specific economic espionage charges but found guilty of trade secret theft, prosecutors file their sentencing memorandum calling for over five years of incarceration.
The Prosecution’s Argument: A Matter of National Security and Deterrence
In their sentencing memo, federal prosecutors argue that Ding’s actions were not a momentary lapse in judgment but a calculated, multi-year effort to strip-mine Google’s intellectual property for personal gain. The government contends that the 63-month recommendation is consistent with the Federal Sentencing Guidelines, given the extraordinary value of the stolen information.
"The defendant did not just steal code; he stole the blueprint for the most advanced AI infrastructure in the world," the prosecution stated. They argue that the potential "intended loss" to Google exceeds many millions of dollars, a factor that significantly increases the suggested sentence under federal law. Furthermore, the government points to the national security implications. As AI becomes a foundational technology for both economic prosperity and military capability, the unauthorized transfer of such technology to foreign competitors is viewed by the DOJ as a threat to the United States’ technological lead.
The prosecution also highlighted the "sophisticated means" used to conceal the crime, including the use of intermediary applications to mask data transfers and the deceptive nature of Ding’s dual employment. They argue that a lenient sentence would send a dangerous signal to the tech industry that the rewards of trade secret theft outweigh the legal risks.
The Defense Response: Contesting the Valuation of Stolen Data
The defense team for Linwei Ding has presented a starkly different interpretation of the facts. They argue that the government’s request for a five-year sentence is "draconian" and disconnected from the actual harm caused. The core of the defense’s argument rests on the assertion that there is no evidence the stolen files were ever actually used by the Chinese startups or that Google suffered a quantifiable financial loss.
Ding’s attorneys emphasize that he was acquitted of the most serious charges related to economic espionage—which would have required proving he acted with the intent to benefit a foreign government. Without that conviction, the defense argues, the case should be treated as a standard commercial trade secret dispute.
"The government is asking the court to sentence Mr. Ding based on what could have happened, rather than what did happen," the defense filing stated. They contend that the information Ding took was fragmented and that he never successfully monetized the data. Consequently, they are advocating for a sentence of home confinement and probation, arguing that Ding’s lack of a prior criminal record and his personal circumstances make him a candidate for leniency.
The Strategic Importance of Tensor Processing Units (TPUs)
To understand the weight of this case, one must understand the technology involved. Google’s TPUs are not off-the-shelf components; they are proprietary Application-Specific Integrated Circuits (ASICs) designed from the ground up to handle the massive mathematical computations required by neural networks.
While most of the world relies on NVIDIA’s GPUs for AI, Google’s TPUs represent one of the few viable, high-performance alternatives. By controlling both the hardware (the TPU) and the software stack (TensorFlow and specialized orchestration tools), Google can achieve levels of efficiency and speed that are difficult for competitors to replicate.
The stolen files allegedly detailed the architecture of the "TPU v6," a next-generation chip that was still under development at the time of the theft. For a startup or a rival nation to gain access to these designs is equivalent to obtaining the recipe for a competitor’s "secret sauce" before it has even hit the market. This technological context is why the federal government has taken such an aggressive stance in the Ding prosecution.
Broader Implications for the Tech Industry and Global Relations
The sentencing of Linwei Ding occurs against the backdrop of the "Disruptive Technology Strike Force," a joint initiative between the U.S. Department of Justice and the Department of Commerce. Launched in 2023, the strike force is tasked with protecting critical U.S. technologies from being illegally acquired by foreign adversaries.
This case serves as a warning to Silicon Valley firms regarding "insider threats." Traditionally, cybersecurity has focused on external hackers, but the Ding case illustrates that some of the most damaging breaches can come from within. In response, many tech companies are now implementing more rigorous monitoring of employee activity, particularly for those with access to "crown jewel" intellectual property.
Furthermore, the case exacerbates the already tense technological relationship between the U.S. and China. The U.S. has increasingly used export controls and criminal prosecutions to limit China’s access to high-end semiconductor and AI technology. The prosecution of individuals like Ding is a key pillar of this strategy, intended to create a "chilling effect" on the unauthorized transfer of knowledge.
Conclusion: Awaiting the Court’s Decision
As the federal judge prepares to hand down a sentence, the tech and legal communities are watching closely. The decision will set a precedent for how "intended loss" is calculated in the digital age, where the value of a few gigabytes of data can theoretically be worth billions of dollars.
If the judge sides with the prosecution, it will reinforce the government’s message that trade secret theft in the AI sector is a high-stakes crime with severe consequences. If the judge leans toward the defense’s request for leniency, it may signal a judicial skepticism toward the government’s efforts to link corporate theft to broader national security concerns without explicit proof of foreign government involvement.
Regardless of the final sentence, the case of Linwei Ding remains a landmark example of the vulnerabilities inherent in the globalized tech economy. It underscores the difficulty of protecting intangible assets in an era where data can be moved across the globe with a few keystrokes, and where the line between legitimate entrepreneurship and criminal theft is increasingly scrutinized by federal authorities. For Google, and for the wider tech industry, the case is a sobering reminder that the most significant threats to innovation often reside just a few cubicles away.
