SAN FRANCISCO, 24 AUG 2026 — A federal judge has thrown out seven economic espionage convictions against Linwei Ding, the former Google engineer found guilty in January of taking the company's artificial intelligence infrastructure designs, ruling that prosecutors did not prove he knew or intended his conduct would benefit the Chinese government.

Seven convictions for theft of trade secrets stand. Ding is due to be sentenced on 1 September. The distinction between those two sets of counts is the whole substance of the ruling, and most of the coverage has collapsed it.

What was vacated and what stands

Ding was convicted on all fourteen counts in January after an eleven-day trial before United States District Judge Vince Chhabria in the Northern District of California.

Chhabria has now set aside the seven economic espionage counts, each of which carried a statutory maximum of fifteen years and a five million dollar fine, on the ground that the evidence was insufficient on one specific element. He left the seven trade secret theft convictions in place, finding the evidence supported them.

This is not an acquittal. Ding remains convicted on all seven counts of stealing trade secrets and faces sentencing in a fortnight. The judge vacated only the finding that he did it on behalf of a foreign state.

7 vacatedEconomic espionage counts
7 upheldTrade secret theft counts
15 yearsMaximum per vacated count
1 September 2026Sentencing

The element the government could not prove

American law treats stealing a trade secret and stealing it for a foreign government as different offences. The distinction is not severity but an additional element the prosecution has to establish.

Theft of trade secrets requires proof that the defendant took the information knowing it would injure its owner. Economic espionage requires all of that plus proof that he intended or knew the theft would benefit a foreign government, or an instrumentality or agent of one. Absent that, the conduct is theft, however valuable the secret and whoever ends up holding it.

Chhabria found the government had not met that additional burden. The question was never whether Ding took the material, which the surviving convictions establish, but whether the record proved he understood he was acting to the benefit of the Chinese state.

Why nationality and destination were not enough

The prosecution's implicit theory was simple and, on this ruling, insufficient. Ding is a Chinese national, the material was destined for Chinese companies, and China's industrial policy prioritises exactly this technology, so the state must be the beneficiary.

Each of those propositions can be true without the element being satisfied. Chinese firms operating commercially are not automatically instrumentalities of the government, and a national policy that benefits from a theft is not evidence that the thief was acting for the policy. The statute asks what was in the defendant's mind, and inference from nationality and destination does not answer it.

Requiring more than that inference is not a technicality. It is the line between a criminal law about conduct and one that treats a defendant's origin as evidence of intent. A court refusing to bridge that gap on circumstantial national-interest reasoning is enforcing the burden of proof, not indulging a formality.

What was actually taken

The material at issue is more specific, and more valuable, than the shorthand about AI secrets suggests.

Between May 2022 and April 2023, while employed at Google, Ding exfiltrated documentation covering the architecture of the company's custom Tensor Processing Units, the integration of GPU systems, specifications for SmartNIC network interface hardware, and the software that orchestrates those parts into a working supercomputer.

That last item is the real prize. Accelerator designs are the visible prize, but the difficulty in large-scale training infrastructure sits in the layer that schedules work across tens of thousands of chips and keeps them fed. Custom silicon design of this kind is why Google has been willing to commit sums like the US$12.2bn arrangement with Marvell to secure it. A rival with the orchestration documentation saves years that cannot be bought.

The charging decision this constrains

The practical consequence falls on prosecutors rather than on defendants.

Economic espionage charges have been a prominent instrument in American enforcement against technology transfer to China, and they carry both a heavier sentence and a far heavier public message. This ruling says that for an espionage count to stand, the government needs evidence going to the defendant's knowledge of state benefit — direction from an official body, specific tasking, or a programme he knowingly joined.

Where the case is an employee copying files to improve his standing at a new employer, however damaging and whoever that employer is, the available charge is theft. That is a narrower instrument, and it is the one that survived here.

It also cuts against a reading of these prosecutions as reliably producing espionage convictions. A jury convicted on all fourteen counts. The trial judge, applying the legal standard to the same record, found half of them unsupported.

What remains open

Sentencing on the surviving counts has not happened, and the vacated counts remove the heaviest exposure but not the conviction. Whether prosecutors seek review of the ruling is not established. The judge's full reasoning, beyond the sufficiency finding on the intent element, is not summarised in the reporting available.

Nor does this ruling say anything about the underlying facts of what China's chip programme has or has not benefited from. It is a finding about what was proved against one defendant.

What it means from here

For any company whose engineers can read design documentation, the enforcement lesson is uncomfortable. The deterrent that reliably survives judicial scrutiny is the lesser charge, and it arrives years after the files have left.

Ding's access ran for eleven months across 2022 and 2023 before it was addressed. That is the number an employer can actually act on, and it has nothing to do with which statute is charged afterwards. An engineer with legitimate access to accelerator architecture and cluster orchestration documentation is a normal, necessary arrangement; the question is whether bulk retrieval from that corpus looks different from ordinary work in any system that is watching.

The other reading is about the nature of the material. It was not a model, weights or a dataset. It was the hardware architecture, and the orchestration software that makes a fleet of chips behave as one machine. The frontier is increasingly defended at that layer, which means the documents worth protecting most are infrastructure documents, held by infrastructure teams, and often governed as though they were ordinary internal engineering notes.