A federal judge has acquitted former Google engineer Linwei “Leon” Ding on all seven economic-espionage counts tied to Google AI trade secrets, but the seven jury convictions for theft of trade secrets remain intact. The ruling removes the part of the case that accused Ding of stealing technology for the benefit of the Chinese government; it does not erase the finding that he took confidential material connected to Google’s AI supercomputing systems for himself and a China-based venture.

Courthouse News first reported the August 20 decision by U.S. District Judge Vince Chhabria in San Francisco, and Reuters and Bloomberg Law independently reported the same result. Ding remains scheduled for sentencing on September 1, 2026, on the trade-secret convictions. Each surviving count carries a statutory maximum of 10 years in prison and a $250,000 fine, though the actual sentence will depend on federal sentencing guidelines and the court’s assessment of the case.

The distinction is far more than a technical adjustment to a headline. The Justice Department secured a jury verdict in January on 14 counts—seven under the Economic Espionage Act and seven for trade-secret theft—and publicly characterized it as the first conviction involving AI-related economic espionage. Chhabria’s ruling now means that landmark claim no longer stands. The jury’s conclusion that Ding stole Google material survives; the government’s more consequential assertion that he did so with the legally required intent to benefit the People’s Republic of China does not.

A dramatic courthouse scene merges Lady Justice with cloud data, servers, a laptop, chip, and digital checklists.The intent requirement prosecutors did not clear​

Economic espionage under 18 U.S.C. § 1831 is narrower than ordinary trade-secret theft. It requires prosecutors to prove, beyond a reasonable doubt, that a defendant intended or knew the offense would benefit a foreign government, foreign instrumentality, or foreign agent. Trade-secret theft under 18 U.S.C. § 1832 requires proof that the defendant knowingly took protected commercial information to benefit someone other than its owner.

Judge Chhabria concluded that the government had ample evidence for the latter. In his June order rejecting most of Ding’s bid for acquittal or a new trial, he wrote that the trial record offered “overwhelming evidence” that Ding acted to benefit himself and Zhisuan, the company he was forming with a business partner in China. The surviving verdict therefore remains a serious criminal finding, not an unresolved accusation.

But the government tried to bridge that commercial motive to a state-benefit motive with later evidence: presentations in late 2023, claimed connections with Chinese state-linked entities, and a December 2023 application to a government-backed talent program. The judge ruled that those acts came too long after the file transfers—between roughly May 2022 and April 2023—to establish what Ding intended at the time of the thefts.

That timing was decisive. A later plan to pursue government funding, state-linked customers, or a talent-program application can be relevant evidence. It is not automatically proof that an earlier document download or cloud upload was undertaken to benefit a foreign government. Chhabria found the prosecution’s chronology too speculative under the criminal reasonable-doubt standard.

The court’s conclusion is a useful reminder for security teams and corporate investigators: evidence that demonstrates unauthorized data removal may be straightforward, while evidence explaining who was meant to benefit can be substantially harder to establish. Those are separate questions in both criminal law and incident response.


The court did not question the theft verdict​

The technology at issue was not generic AI research or publicly available machine-learning code. The Justice Department said the materials concerned Google’s infrastructure for training and serving large AI models, including Tensor Processing Unit systems, GPU systems, software that coordinates chips and workloads, and SmartNIC networking technology used in AI supercomputers and cloud networking products.

According to the Justice Department’s January announcement, Ding worked at Google from 2019 and transferred thousands of pages of confidential material while still employed. The department said he uploaded documents from Google’s internal environment to a personal Google Cloud account, then downloaded material onto a personal computer in December 2023, shortly before leaving the company. The original 2024 indictment also alleged that Ding arranged for another person to badge into Google facilities to make it appear he remained at work while he was in China.

Those allegations mattered at trial because the jury was asked to decide whether Ding knowingly appropriated protected technical information for someone other than Google’s benefit. The jury answered yes on all seven trade-secret categories. Chhabria left those verdicts in place after reviewing Ding’s post-trial motions.

For enterprise IT administrators, the file path described in the case is uncomfortably familiar: internal documents copied into a laptop notes application, converted to PDFs, uploaded to a personal cloud account, and later moved to a personal device. The alleged movement was not a sophisticated network intrusion. It was an insider using access that came with the job, then moving data through services and file formats that can look routine in isolation.

That is why the operational lesson is not simply “block cloud storage.” A blanket block can disrupt legitimate development and collaboration, while determined insiders may use email, removable media, screenshots, code snippets, personal accounts, or ordinary productivity tools. The defensible control is layered monitoring around sensitive repositories, unusual bulk access, off-pattern downloads, external sharing, and changes in employment or travel risk.

The government’s alternate theory arrived too late​

The government had another route available: argue that Ding possessed the requisite intent when he downloaded the documents from his personal cloud account to his personal laptop in December 2023. By then, prosecutors had more evidence of his commercial plans in China and his interest in government-supported programs.

Chhabria rejected that route because prosecutors did not present it to the jury as the basis for the economic-espionage counts. The trial, he wrote, focused on Ding’s state of mind when he initially uploaded the materials during the 2022-to-2023 period. A court cannot preserve a conviction after the fact by adopting a factual theory the prosecution did not actually put before jurors.

This is the part of the decision most likely to matter beyond Ding’s sentence. The judge did not hold that a transfer from personal cloud storage to a private laptop could never support an economic-espionage charge. He held that this prosecution could not substitute a different episode and mental-state theory after the jury had been instructed and deliberated on another one.

Because the judge granted an acquittal for insufficient evidence rather than ordering a new trial, double-jeopardy protections prevent the government from retrying Ding on the seven economic-espionage counts. The Department of Justice had not publicly commented on the ruling when Courthouse News and Reuters published their reports.

The collapse of those counts also changes the maximum statutory exposure. The original economic-espionage counts each carried up to 15 years in prison and up to a $5 million fine. They are gone. Ding still faces seven trade-secret counts, each with a maximum 10-year prison term and $250,000 fine, but courts do not mechanically stack maximum penalties, and sentencing is not a simple multiplication exercise.


A criminal case is not a security-control audit​

The public record gives a clear picture of the alleged data exfiltration and the criminal evidence, but it does not establish that Google lacked basic security controls. In fact, the 2024 indictment described Google identifying anomalous activity, recovering company devices, and cooperating with the FBI. The case should not be read as a finding that Google’s security program failed wholesale.

It does show the limits of relying on any single detection point. A capable insider may have legitimate access to documents, may touch files gradually rather than in one massive export, and may repurpose ordinary tools—notes software, PDF export, cloud sync and personal devices—as a data-transfer chain. The unauthorized act can blend into a workflow until access patterns, destination accounts, timing, or volume reveal a larger pattern.

Organizations protecting source code, chip designs, AI training infrastructure, model weights, customer data, or internal architecture documents should treat departing employees and employees developing outside business interests as a high-value review point. The review should be narrowly targeted and legally vetted, but it should include repository access, bulk export history, external cloud sharing, forwarding rules, device posture, credential resets, and preservation of logs before access is removed.

The Ding decision also separates a security conclusion from a geopolitical conclusion. The evidence supported that Google’s confidential AI infrastructure information was stolen to benefit Ding and his planned company. The evidence did not, in Judge Chhabria’s view, prove beyond a reasonable doubt that the thefts were undertaken to benefit the Chinese government. Companies should resist collapsing those two findings into one. Doing so may make for a sharper headline, but it is precisely the evidentiary leap the court rejected.

Ding’s September 1 sentencing will determine the immediate criminal consequence for the surviving trade-secret convictions. The longer consequence is already clear: in high-value AI and cloud infrastructure cases, prosecutors can prove an insider took data and still fail to prove foreign economic espionage unless the evidence ties the defendant’s intent to a foreign state at the moment the theft occurred.