By Jeffrey A. Newman, Esq. MBA with AI assistance
In the space of about eighteen months, three Chinese laboratories ran more than sixteen million conversations with an American artificial intelligence system through roughly twenty-four thousand fraudulently created accounts. A Chinese state-sponsored group jailbroke a different American AI and turned it into the operator of an espionage campaign against some thirty companies and government agencies, with the machine performing eighty to ninety percent of the intrusion work itself. Somewhere between 290,000 and 1.6 million American AI chips were smuggled into a country legally barred from buying them — on the median estimate, enough silicon to account for roughly a third of all the computing power China possesses. A former Google engineer was convicted of stealing the designs for the machines on which American AI is built. And the best American model now leads the best Chinese model by 2.7 percent, on twenty-three times the money.
None of that is speculation. Every item is drawn from federal indictments, court records, disclosures the AI companies made about themselves, or measurement by independent research organizations.
What follows is an account of how this is being done, who in China is doing it, why almost none of it can be stopped by a lawsuit, and what the United States has already decided not to do about it.
I. The Badge Scan
On a workday in late 2023, a Google employee in Mountain View walked to a badge reader and scanned a colleague’s credential. The colleague, a software engineer named Linwei Ding, was not in California. He was in Beijing.
The scan was a small courtesy. It made the building’s access logs show a man at his desk who was, at that moment, on the other side of the Pacific, raising money from Chinese investors for a company he had founded and told no one at Google about.
It is a small detail, and it is the most human thing in this entire story. Someone did a favor for a friend. But that favor held open a door, and what walked through it were the designs for the machines on which American artificial intelligence runs.
Ding was convicted on January 29, 2026, in a San Francisco federal courtroom, on seven counts of economic espionage and seven counts of theft of trade secrets. It was, the Justice Department said, the first conviction on AI-related economic espionage charges in American history.
It may also be among the last cases of its kind that matters very much. The theft has moved on.
What that means concretely is this. Ding had to copy files and carry them out of a building. The channel that now moves the most valuable American AI capability across the Pacific requires no files, no copying, and no employee. It comes through the front door as a paying customer. Whether it is even illegal has never been tested in an American court.
Google hired Ding in 2019 to work on the operation of its supercomputers — the systems that let thousands of custom chips behave as a single machine and train a large AI model, over weeks of continuous computation, without the whole run collapsing.
This is unglamorous work and it is the crown jewels. Anyone can read a paper about transformers. Almost no one on earth knows how to make forty thousand accelerators cooperate for six weeks without a fatal desynchronization.
Between May 2022 and April 2023, prosecutors said, Ding moved more than two thousand pages of that knowledge out of Google’s network and into his personal cloud account: the architecture of Google’s Tensor Processing Unit chips, its GPU systems, the software that let the chips talk to one another, the cluster management software, its custom network interface card designs.
He did it while being courted. Within weeks of the first uploads, according to the indictment, a Chinese machine-learning startup called Rongshu offered him the chief technology officer’s job at 100,000 renminbi a month — roughly $178,000 a year at the time — plus bonus and equity.
He traveled to China in October 2022 and stayed until the following March, meeting investors. By May 2023 he had founded a second company, Shanghai Zhisuan Technology, and made himself its chief executive. Its product was to be a cluster management system for accelerating machine learning.
He applied to a Chinese government talent program. In the application, prosecutors told the jury, he wrote that he intended to help China build computing infrastructure on par with the international level.
Now the question that ought to be asked more often than it is: what did Google know, and when did it know it?
The answer, on the government’s own timeline, is not flattering. The uploads ran for eleven months. Google’s internal investigation did not begin because a security system caught them. It began because Ding surfaced at an investor conference in Beijing, introduced from the stage as a chief executive of a company Google had never heard of.
He resigned before the company finished looking. He had already booked a one-way ticket.
At trial, his lawyer, Grant Fondo of Goodwin Procter, turned that timeline into the defense. Ding never sold, transferred, or used any of the material, Fondo argued; investors passed on both ventures. And Google itself had labeled the documents inconsistently and made them available to hundreds of thousands of employees. Google, he told the jury, chose openness over security.
The jury convicted on all fourteen counts. But hold onto the defense argument, because it points at something the enforcement statistics obscure.
II. Nobody Bought It
A reasonable person, reading about this case, asks the obvious question: who paid him?
It is the question that structures every spy story we know. There is the insider, and there is the handler, and there is the money.
The honest answer, and it took some looking to be confident of it, is that in the American AI sector there is no publicly known case fitting that shape. Not one.
Search the Justice Department’s records and you find real prosecutions, but they are a different animal. Chenguang Gong, a San Jose engineer, pleaded guilty in 2025 to taking more than 3,600 files on infrared missile-warning sensors and radiation-hardened space cameras — defense technology, not AI, and he used the material to pitch himself to Chinese talent programs rather than to sell it to a buyer. Apple has had autonomous-vehicle engineers charged. Tesla has had battery secrets taken.
What you do not find is the thing people imagine: an engineer at a frontier AI lab meeting an intelligence officer in a parking structure and handing over a drive of model weights for cash.
I want to be careful here. Absence of a public case is not absence of a case. Counterintelligence investigations are sealed. Companies settle quietly, because disclosing that your weights walked out the door is an admission no board wants to make.
But the pattern in the public record is consistent, and it is not the pattern of bribery. It is the pattern of ambition.
Ding was not paid to steal. He was building something, and he wanted a running start, and China had constructed an elaborate apparatus of talent programs, incubators, and capital designed precisely to reward a man in his position for having one.
That is a harder problem than corruption. You can defend against a bribe. It is considerably more difficult to defend against a thirty-eight-year-old engineer who has decided he would rather be a founder than an employee, and who happens to know how the cluster works.
III. The New Way Requires No Burglar
Now set Ding aside, because while the government was preparing his case, the method that actually moves capability across the Pacific was being industrialized, and it does not require anyone to steal anything in the ordinary sense.
No badge. No accomplice at the reader. No lock at all.
It is called distillation, and the concept is old and entirely respectable. You have a large, expensive, capable model — the teacher. You want a smaller, cheaper model — the student. So you ask the teacher millions of questions, collect its answers, and train the student on those answers until the student imitates the teacher’s behavior.
Every major lab does this. DeepSeek’s own published research distills its models into smaller ones. Nvidia distills. The technique is in the textbooks.
The objection is not to the method. It is to whose teacher you use.
On February 23, 2026, Anthropic published what remains the most detailed public account of the practice. It said it had identified roughly 24,000 fraudulently created accounts running more than sixteen million exchanges with its Claude models, and it named three Chinese laboratories: DeepSeek, Moonshot AI, and MiniMax.
MiniMax accounted for the overwhelming share — more than thirteen million exchanges. Moonshot, more than three million. DeepSeek, a comparatively modest hundred and fifty thousand.
Anthropic does not sell Claude in China. The traffic came through commercial proxy services that resell frontier model access, layered through networks of accounts designed to look like ordinary customers.
Two details in that disclosure deserve more attention than they got.
The first is that Anthropic said it traced accounts to specific researchers, and that in Moonshot’s case the request metadata matched the public profiles of senior staff. This was not a contractor operation run at arm’s length. It was, by Anthropic’s account, the research team itself.
The second is the reflex. Anthropic said it caught MiniMax mid-campaign, before the model being trained had shipped. When Anthropic released a new model during the campaign, MiniMax redirected nearly half its traffic to the new system within twenty-four hours.
Think about what that requires. Somebody was watching the release feed. Somebody had built the harvesting pipeline to be repointed on a day’s notice. This is not opportunism; it is operations.
Eleven days earlier, OpenAI had made a parallel filing to the House Select Committee on the Chinese Communist Party, alleging that DeepSeek-affiliated accounts had routed around access restrictions through obfuscated third-party routers and unauthorized resellers, and that its staff had written code to harvest outputs programmatically.
OpenAI also described a technical escalation worth understanding. The early version of this was crude imitation: copy the answers. The current version harvests reasoning traces — the model’s step-by-step working — and feeds them through multi-stage pipelines that generate synthetic training data and run preference optimization on top.
The distinction matters. Imitating answers gives you a mimic. Imitating the reasoning gives you something closer to the underlying judgment — the part that took the years and the billions.
IV. What Is Actually Being Taken
There are three things moving, and conflating them is the most common error in the public conversation.
The first is judgment. That is distillation, described above. It is the largest channel by volume and the hardest to characterize legally, because every individual query is a lawful transaction with a willing seller.
The second is design. This is the part that should unsettle engineers rather than lawyers.
At the 2024 International Conference on Machine Learning, researchers from Google DeepMind, ETH Zurich, and elsewhere presented work showing that parts of a production language model can be recovered through the public API alone — no insider, no breach. By exploiting the logit-bias and log-probability surface that commercial APIs expose, they recovered the exact hidden dimension and the final embedding projection layer of live models. For OpenAI’s Ada and Babbage, the cost was about twenty dollars. They estimated the full projection matrix of gpt-3.5-turbo at under two thousand.
That is cryptanalysis, performed against a model, by a paying customer.
The hardware side is stranger. At the Network and Distributed System Security Symposium in 2026, researchers presented an attack called ModelSpy that reads a neural network’s architecture off a running GPU through its electromagnetic emissions. The antenna fits in a bag. It worked from as far as six meters, through walls, across multiple GPU types, identifying core structures with up to 97.6 percent accuracy. An earlier attack out of North Carolina State University, TPUXtract, recovered a full architecture from a Google Edge chip with 99.91 percent accuracy.
Here I want to stop the escalator, because this is where these stories usually go wrong.
No public attack has extracted the full weights of a frontier-scale model through a side channel or an API. Not one. What has been proven is the recovery of architecture, hyperparameters, and partial or final-layer weights — the TPUXtract authors are explicit that their attack does not obtain the weights, which are the expensive product of training. Anyone telling you that China can lift a complete model off a running cluster by pointing an antenna at a building is selling something.
The real finding is narrower and still serious: the design of a model — the part discovered through failed runs nobody publishes — leaks more readily than almost anyone assumed.
The third is silicon. This is the only channel that behaves like conventional smuggling, and it is the one where American companies, American employees, and American law all meet in the same room. It is where this article ends, so hold it for now.
Understand only why it exists, and how much has moved.
China’s best domestic accelerator, Huawei’s Ascend 910C, is built on SMIC’s second-generation seven-nanometer process — a level of manufacturing capability TSMC reached around 2019 and 2020. Testing by DeepSeek’s own researchers put the chip at roughly sixty percent of an H100’s inference performance. If you cannot compute the capability, you buy the chips illegally or you copy the capability from someone who already computed it.
China has been doing both. In April 2026, the research organization Epoch AI published an estimate that between 290,000 and 1.6 million H100-equivalent chips were smuggled into China through the end of 2025. Its median estimate, 660,000 units, would amount to roughly a third of all the AI computing power China has.
And then there is a fourth thing, which is not being taken at all. It is being used.
In mid-September 2025, Anthropic detected what it later described as the first reported AI-orchestrated cyber espionage campaign. A group it designated GTG-1002, which it assessed with high confidence to be Chinese state-sponsored, jailbroke Claude Code by convincing it that it was performing defensive security testing for a legitimate firm, then decomposed the attack into subtasks innocuous enough to pass individually.
The system attempted intrusions against roughly thirty targets — large technology companies, financial institutions, chemical manufacturers, and government agencies — and succeeded against a small number. Anthropic estimated that the AI executed eighty to ninety percent of the tactical work itself, with human operators intervening at only a handful of decision points per intrusion.
That is a different category from anything else in this article. Distillation copies the capability. Smuggling moves the hardware. This was an American frontier model, accessed as a customer, pointed back at American institutions and run at machine speed.
V. Who Is Doing This
Here the story turns, and it turns in a direction that makes the enforcement framing uncomfortable.
The people at the center of China’s AI effort are not operatives. They are, by any fair reading, some of the best researchers alive, and several of them were trained here.
Liang Wenfeng founded DeepSeek out of High-Flyer, the quantitative hedge fund he runs from Hangzhou. This is why DeepSeek behaves unlike a normal company: it is subsidized by a trading firm and does not need outside capital. It publishes its weights openly. Liang has said in interviews that China should stop adopting foreign technology and start producing breakthroughs — a statement of injured pride as much as strategy.
Yang Zhilin founded Moonshot AI at thirty-three. He holds a degree from Tsinghua and a doctorate from Carnegie Mellon. He named the company after a Pink Floyd album. Moonshot’s Kimi models have repeatedly topped open-weight benchmarks.
Yan Junjie founded MiniMax after working on computer vision at SenseTime. MiniMax was among the first Chinese labs to run mixture-of-experts architecture at scale — an approach DeepSeek later popularized. It listed in Hong Kong in January.
Tang Jie, a Tsinghua professor, co-founded Zhipu AI — now Z.ai — in 2019 with colleagues and alumni. Zhipu is the most explicitly state-adjacent of the group, earning most of its margin from on-premises deployments for Chinese state-owned enterprises rather than from API sales.
Behind them sit Alibaba’s Qwen team and ByteDance’s Seed group, both operating at genuine frontier scale. Stanford’s 2026 AI Index measured the top Chinese model on the Arena leaderboard as ByteDance’s, not DeepSeek’s. In February 2026 the Defense Department added Alibaba and Baidu to its list of Chinese military companies.
Now the numbers that reframe everything.
MacroPolo’s Global AI Talent Tracker, which classifies elite researchers by where they did their undergraduate work, found that China’s share of the world’s top-tier AI researchers rose from twenty-seven percent in 2017 to thirty-eight percent by 2024. American institutions still employ a majority of elite AI researchers — but that majority holds up almost entirely through imported talent. China-educated researchers now make up a larger share of elite AI scientists working in the United States than American-educated ones.
For years the arrangement was stable, because the best Chinese students came here and stayed. Roughly seventy percent still work in American institutions.
What has changed is the flow. Stanford’s AI Index found that the number of AI researchers entering the United States has fallen eighty-nine percent over seven years — and eighty percent in the past year alone — a decline the report attributes in part to visa restrictions. Better labs at home, competitive pay, and the demonstration effect of DeepSeek have made staying in China a reasonable choice rather than a concession.
And more than half of the authors on DeepSeek’s papers were educated and employed entirely in China, with no overseas training at all.
That is the finding that should worry people more than any indictment. The talent pipeline no longer depends on us.
Which produces the central awkwardness of the whole enforcement posture: the same researchers who allegedly ran the harvesting campaigns publish their architectures openly, release their weights for anyone to download, and are cited approvingly in American papers. They are competitors and colleagues at once. The distillation dispute is not a spy story. It is a fight among peers about the terms of service.
VI. Why Nobody Has Sued
American labs can see all of this happening. That is the strange part.
Detection is genuinely good. Stylometric fingerprinting matches a suspect model’s writing signature against a teacher’s. Traffic analysis catches the distinctive shape of harvesting — enormous volume concentrated on narrow capabilities, repetitive prompt structures, coordinated accounts correlated by IP and metadata. OpenAI, Anthropic, and Google now share distillation intelligence through the Frontier Model Forum.
When Anthropic banned the offending accounts, replacements appeared within hours.
Seeing and stopping are different capabilities, and the United States is strong on one and weak on the other. The reason is legal, and it is worth walking through, because the public assumes remedies exist that do not.
Contract. The terms of service prohibit using outputs to train competing models. That prohibition is real and immediately available. It is also a contract claim against an offshore entity, which raises personal jurisdiction problems at the front end and enforcement problems at the back. A judgment is worth what a court can seize.
Trade secrets. This is the strongest theory, and it is untested. Under Compulife Software v. Newman (11th Cir. 2020), using a bot to scrape a quantity of data no human could feasibly gather can constitute acquisition by improper means, even when every individual data point is publicly available. Applied to distillation, mass output harvesting to reconstruct a model’s capabilities is arguably not arms-length reverse engineering, and the terms-of-service breach strengthens it. The counter is straightforward: each query was individually authorized and paid for. No American lab has litigated it.
Copyright. Largely unavailable. The Copyright Office holds that purely AI-generated works are not copyrightable, so the outputs themselves are generally unprotected.
Patents. The remedy people most often assume will work, and the most misunderstood. A patent holder can seek a Section 337 exclusion order from the International Trade Commission — a genuinely powerful tool that bars infringing products at the border. But under the Federal Circuit’s ClearCorrect decision, electronic transmissions and pure digital data are not “articles” the ITC can exclude. A model, its software, and its weights fall outside that jurisdiction. Section 337 reaches AI hardware. It does not reach a model provider with no importable good.
This is why no American AI lab has sued a Chinese one. Both OpenAI and Anthropic chose public accusation and lobbying instead. They ran the math.
The one lever with real force is not damages. It is denial of access — Entity List designation, cloud restrictions, sanctions. The United States hosts roughly three-quarters of the world’s AI supercomputing capacity, against China’s fifteen percent, and that is the actual asymmetry.
Which brings up the sharpest fact in the story.
In June 2026, Reuters reported that an interagency committee — drawing on Commerce, Defense, Energy, and State — had approved DeepSeek, the memory chipmaker CXMT, and more than a hundred other Chinese companies for addition to the Commerce Department’s Entity List. Commerce never published the designations. The reporting attributed the hold to an effort to avoid escalating trade tensions with Beijing.
A senior State Department official had told Reuters that DeepSeek has supported China’s military and intelligence operations and had tried to use Southeast Asian shell companies to obtain restricted American chips.
At the time of that reporting, the United States had not added a single company to the Entity List since the previous October — the longest gap in more than a decade.
The most consequential instrument the government has was loaded and set down.
VII. If They Pull Ahead
Now the question that actually matters, and it deserves a more honest answer than the usual one.
Start with what is measured rather than predicted. Stanford’s 2026 AI Index put the gap between the top American and top Chinese models on the Arena leaderboard at 2.7 percent as of March 2026 — thirty-nine rating points between Anthropic’s Claude Opus 4.6 and ByteDance’s Dola-Seed-2.0-Preview. In May 2023 the spread across major benchmarks had run between 17.5 and 31.6 percentage points. Epoch AI, measuring differently, finds that Chinese models have trailed the American frontier by an average of seven months since 2023, with the gap never exceeding fourteen.
Set that beside the money. American private AI investment ran $285.9 billion in 2025 against $12.4 billion in China — a ratio of about twenty-three to one.
A twenty-three-to-one spending gap has produced a 2.7 percent capability gap. That ratio is the whole argument, and it points at a structural asymmetry rather than a temporary one.
The economics underneath it are brutal and well documented. Epoch AI’s cost modeling shows the amortized cost of training a frontier model growing at about 2.4 times a year since 2016, with the largest runs projected to pass a billion dollars by 2027. Meanwhile the price of reaching any fixed level of capability has collapsed — Epoch measured declines between nine and nine hundred times a year across benchmarks, with a median near fifty.
Leading gets more expensive every year. Following gets cheaper every year. Distillation sits on the favorable blade of those scissors.
The practical consequence is that any American frontier capability becomes cheaply reproducible within a year or two of release, and the American firm bears the entire research cost while a fast follower captures much of the value at a fraction of the spend.
The second consequence is already visible in the world’s software, and the cleanest measure of it is not downloads but derivatives — what developers actually build on.
Alibaba’s Qwen overtook Meta’s Llama in cumulative downloads in September 2025. By early 2026, Qwen’s share of newly created fine-tunes and adaptations had risen to sixty-nine percent, up from one percent two years earlier. Meta’s share, which peaked at forty-four percent, had fallen to eleven.
That is what it looks like when the world’s default substrate changes hands.
The qualifier keeps this from being overstated. Enterprises have not followed. Menlo Ventures’ survey of enterprise LLM usage found open-source models holding only about eleven percent of the market, and Chinese models accounting for roughly one percent of total enterprise API usage. American models still own the paid, regulated, audited layer.
So the likely shape is a split market: American models holding enterprise trust and paid inference, Chinese open weights owning the free, embedded, and developer-default layer.
That second layer is the one you cannot claw back. When a Chinese model becomes the foundation for the world’s fine-tuning, its design choices and its safety behavior propagate into products everywhere, including American ones.
Which raises the last consequence, and the one that is a safety problem rather than a competitiveness problem. A distilled model inherits capability without inheriting the alignment work. The guardrails are not in the outputs you harvest. They are in the training you skipped. The Future of Life Institute’s mid-2026 AI Safety Index gave failing grades to three companies — xAI in the United States, Mistral in Europe, and DeepSeek in China.
So the plausible three-year picture is not Chinese domination. It is something more corrosive: an American compute advantage that keeps widening alongside a capability gap that keeps narrowing, with the world’s default AI infrastructure drifting toward systems built by people who publish less safety work and answer to a government that has designated their commercial partners as military companies.
And the single variable that most changes that picture is not technical. It is whether we enforce controls we have already written.
Which brings us to the chips, and to the harder question.
VIII. What We Do Not Know
There is a phrase in export control law that does not sound like much until you sit with it.
The Export Administration Regulations define “knowledge” at 15 C.F.R. § 772.1. Knowing something, the regulation says, includes not only positive knowledge that a circumstance exists but awareness of a high probability that it exists. And that awareness can be inferred two ways: from conscious disregard of facts a person already has, and from a person’s willful avoidance of facts.
Read that last clause again. Avoiding the facts is a way of knowing them.
This is not an exotic doctrine. Ordinary life is full of it. The pawnbroker who does not ask why a man is selling six identical laptops at nine in the morning has, in a sense the law recognizes, been told.
The regulations are unusually blunt about what this means for a company. Supplement No. 3 to Part 732 instructs firms not to cut off the flow of information that reaches them in the normal course of business. Do not tell the sales force to steer customers away from discussing the real end use. Do not put on blinders. An affirmative policy of avoiding bad information, the regulation says, would not insulate a company from liability and would usually be treated as an aggravating factor.
The same section adds one more line, and it is the one that should interest anyone reading this from inside a large company. Knowledge possessed by an employee can be imputed to the firm.
So the law does not require a memo. It does not require a meeting. It asks a narrower and more uncomfortable question: what did the company arrange not to find out?
Now set the doctrine aside and look at what is on the public record.
On March 19, 2026, federal prosecutors in the Southern District of New York unsealed an indictment charging Super Micro co-founder Yih-Shyan “Wally” Liaw, a Taiwan-based sales manager, and a contractor described as a third-party broker with conspiring to divert servers containing restricted Nvidia GPUs to China without licenses.
The numbers are large. Liaw and his co-defendant directed executives of a Southeast Asian company to place roughly $2.5 billion in server orders across 2024 and 2025. That pass-through company repackaged the boxes and sent some $510 million worth of servers with controlled chips on to China.
The methods described by the government are almost slapstick, and that is what makes them worth repeating. The FBI’s assistant director in charge of the New York field office said the defendants used fabricated documents, staged bogus equipment to pass audit inventories, and ran everything through a pass-through company to conceal the real customer list. According to the indictment, one defendant sent photographs and video of staged dummy servers to a compliance auditor who was off-site at the time, enjoying entertainment paid for by the pass-through company. Surveillance footage captured people using hair dryers to lift shipping labels off boxes and replace them.
Liaw has pleaded not guilty. His trial is scheduled for November 2, 2026. His co-defendant Chang remains a fugitive. Super Micro was not charged, said the alleged conduct violated its own policies and compliance controls, and stated it is cooperating.
Five months later, on August 24, 2026, the Keelung District Prosecutors’ Office in Taiwan indicted nine people in a structurally similar case, one that grew out of a joint investigation with the U.S. Justice Department.
The hardware this time was the B300, Nvidia’s Blackwell Ultra accelerator, which the Bureau of Industry and Security classifies under a presumption that any license application for China will be denied. The defendants included a manager at Nvidia’s Taiwan office, two Super Micro sales managers in Taiwan, and the chief executive of Albatron Technology, a Super Micro distributor.
The scheme was documentary rather than technical. No hacking, no counterfeit hardware. Paperwork stating that 130 servers would remain inside Taiwan.
Seventy-four of them left. Fifty went through Indonesia, sixteen shipped directly, and eight moved through a shell company in Japan and then Hong Kong before reaching Chinese buyers. Proceeds on the completed shipments came to roughly $21 million. Customs stopped the remaining fifty-six.
Here is the part that matters most.
According to the prosecutors’ account, buyers of Super Micro servers containing B300 chips had to clear an Nvidia whitelist process, supply end-user and end-use documentation, and agree not to resell. For orders of eight servers or more, Nvidia and Super Micro personnel were expected to conduct a physical site inspection.
The controls existed. They were not decorative. Prosecutors allege the defendants shared information about how the review process worked among themselves and then falsely represented that the inspection had been performed. The Nvidia manager, prosecutors said, was the person who authorized release of the chips.
Taiwan, it turned out, has no statute that directly criminalizes exporting AI hardware. The nine were charged with breach of trust and document forgery.
Now the necessary sentence, and I want to write it plainly rather than bury it.
We do not have evidence that Nvidia knew where these chips were going. We do not have evidence that any American chipmaker knew that its sales would end up in China.
Neither Nvidia nor Super Micro has been charged as a corporate entity in either case. Both have described the conduct as that of individuals rather than company policy. Nvidia has stated in its most recent annual report that it has been effectively excluded from the China data center computing market, and its chief executive has said publicly that its share of that market is zero. Whatever else is true, a company shut out of a market is a strange candidate for the theory that it is quietly protecting revenue there.
The compliance procedures at issue in Taiwan were Nvidia’s own. Somebody wrote them. Somebody required a site inspection for orders above a threshold. That is not the behavior of an organization that does not care.
What the record shows is a set of controls that existed on paper and failed at the point where a human being had to look at a warehouse and say what he saw. Whether that is the ordinary failure of any system operated by people, or something that grew in soil where nobody was especially eager to dig, is not a question the public record answers. It is not a question I am going to answer for you.
What I will say is this.
This country needs to build artificial intelligence, and it needs to build it well and build it first. The stakes are as high as they have been in the lifetime of anyone reading this — for the nation, for its economy, and for the shape of the world order that follows.
The hyperscalers need this too.
Sources
The Ding prosecution
- U.S. Department of Justice, “Former Google Engineer Found Guilty of Economic Espionage and Theft of Confidential AI Technology” (Jan. 30, 2026): https://www.justice.gov/opa/pr/former-google-engineer-found-guilty-economic-espionage-and-theft-confidential-ai-technology
- U.S. Attorney’s Office, N.D. Cal., same release: https://www.justice.gov/usao-ndca/pr/former-google-engineer-found-guilty-economic-espionage-and-theft-confidential-ai
- DOJ, superseding indictment release: https://www.justice.gov/opa/pr/superseding-indictment-charges-chinese-national-relation-alleged-plan-steal-proprietary-ai
- United States v. Ding, N.D. Cal. No. 24-cr-00141
- Courthouse News, trial coverage and defense arguments: https://www.courthousenews.com/jury-finds-ex-google-engineer-guilty-of-stealing-ai-trade-secrets-for-chinese-companies/
- The Register, Rongshu compensation and Shanghai Zhisuan details: https://www.theregister.com/2026/01/30/google_engineer_convicted_ai_secrets_china/
- The Register, Chenguang Gong guilty plea: https://www.theregister.com/2025/07/22/engineer_admits_trade_theft/
Distillation and the AI-orchestrated campaign
- Anthropic distillation disclosure (Feb. 23, 2026), via CNBC: https://www.cnbc.com/2026/02/24/anthropic-openai-china-firms-distillation-deepseek.html
- CNN on the same disclosure: https://www.cnn.com/2026/02/24/tech/anthropic-chinese-ai-distillation-intl-hnk
- Per-lab attribution and the 24-hour MiniMax pivot: https://www.how2shout.com/news/anthropic-accuses-deepseek-moonshot-minimax-distillation-attack.html
- Foundation for Defense of Democracies on OpenAI’s memo to the House Select Committee (Feb. 12, 2026), and the DoD Chinese military company listings: https://www.fdd.org/analysis/2026/02/13/openai-alleges-chinas-deepseek-stole-its-intellectual-property-to-train-its-own-models/
- Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign” (Nov. 13, 2025): https://www.anthropic.com/news/disrupting-AI-espionage
- Full Anthropic report (PDF): https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf
- Cybersecurity Dive on GTG-1002: https://www.cybersecuritydive.com/news/anthropic-state-actor-ai-tool-espionage/805550/
- MITRE ATT&CK, Campaign C0062: https://attack.mitre.org/campaigns/C0062/
Model extraction and side channels
- Carlini et al., “Stealing Part of a Production Language Model,” ICML 2024
- “Peering Inside the Black-Box: Long-Range and Scalable Model Architecture Snooping via GPU Electromagnetic Side-Channel” (ModelSpy), NDSS 2026: https://www.ndss-symposium.org/ndss-paper/peering-inside-the-black-box-long-range-and-scalable-model-architecture-snooping-via-gpu-electromagnetic-side-channel/
- Kurian, Dubey, Yaman & Aysu, “TPUXtract: An Exhaustive Hyperparameter Extraction Framework,” IACR TCHES: https://tches.iacr.org/index.php/TCHES/article/view/11923
China’s labs, talent base, and hardware
- MacroPolo, Global AI Talent Tracker: https://archivemacropolo.org/interactive/digital-projects/the-global-ai-talent-tracker
- Carnegie Endowment, “Have Top Chinese AI Researchers Stayed in the United States?”: https://carnegieendowment.org/emissary/2025/12/china-ai-researchers-us-talent-pool
- South China Morning Post on Moonshot and MiniMax: https://www.scmp.com/tech/big-tech/article/3334602/beyond-deepseek-moonshot-and-minimax-step-chinas-new-frontier-ai-labs
- Fortune on the founders: https://fortune.com/2026/07/26/china-moonshot-deepseek-zai-kimi-challenging-us-ai-cost/
- Dealroom on Zhipu’s state-enterprise model: https://dealroom.co/news/136199-inside-chinas-ai-ecosystem-beyond-deepseek-zhipu-minimax-moonshot-byteda/
- Tom’s Hardware on DeepSeek’s testing of the Ascend 910C: https://www.tomshardware.com/tech-industry/artificial-intelligence/deepseek-research-suggests-huaweis-ascend-910c-delivers-60-percent-nvidia-h100-inference-performance
Measurement and market position
- Stanford HAI, 2026 AI Index Report: https://hai.stanford.edu/ai-index/2026-ai-index-report
- Epoch AI, “Diversion and resale: estimating compute smuggling to China” (Apr. 29, 2026): https://epoch.ai/publications/chip-smuggling
- Epoch AI, “Chinese AI models have lagged the US frontier by 7 months on average since 2023”: https://epoch.ai/data-insights/us-vs-china-eci
- Epoch AI, “Trends in AI Supercomputers” (U.S. and China shares of global capacity): https://epoch.ai/publications/trends-in-ai-supercomputers
- Cottier et al., “The Rising Costs of Training Frontier AI Models,” Epoch AI / arXiv 2405.21015: https://epoch.ai/blog/how-much-does-it-cost-to-train-frontier-ai-models
- Epoch AI, “LLM inference prices have fallen rapidly but unequally across tasks”: https://epoch.ai/data-insights/llm-inference-price-trends
- The ATOM Report, “Measuring the Open Language Model Ecosystem” (Qwen derivative share): https://arxiv.org/html/2604.07190v1
- Menlo Ventures, “2025: The State of Generative AI in the Enterprise”: https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/
- Future of Life Institute, AI Safety Index, Summer 2026: https://futureoflife.org/ai-safety-index-summer-2026/
Remedies
- Compulife Software, Inc. v. Newman, 959 F.3d 1288 (11th Cir. 2020)
- ClearCorrect Operating, LLC v. ITC, 810 F.3d 1283 (Fed. Cir. 2015)
Knowledge and the chip cases
- 15 C.F.R. § 772.1, definition of “Knowledge”: https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-772/section-772.1
- 15 C.F.R. Part 732, Supplement No. 3 (red flags; “do not put on blinders”; imputation of employee knowledge): https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-732
- DOJ (S.D.N.Y.), “Three Charged With Conspiring To Unlawfully Divert U.S. Artificial Intelligence Technology To China” (Mar. 19, 2026): https://www.justice.gov/usao-sdny/pr/three-charged-conspiring-unlawfully-divert-us-artificial-intelligence-technology-china
- DOJ Office of Public Affairs, same: https://www.justice.gov/opa/pr/three-charged-conspiring-unlawfully-divert-cutting-edge-us-artificial-intelligence
- CNN on the staged servers, the entertained auditor, and the hair dryers: https://www.cnn.com/2026/03/19/politics/super-micro-computer-founder-charged-ai-chips-china
- NBC News on the $2.5 billion and $510 million figures: https://www.nbcnews.com/tech/tech-news/three-men-charged-illegally-smuggling-advanced-ai-chips-china-rcna264371
- Bloomberg on the Taiwan indictment: https://www.bloomberg.com/news/articles/2026-08-24/taiwan-indicts-nvidia-manager-following-chip-smuggling-probe
- Japan Times, same: https://www.japantimes.co.jp/news/2026/08/25/asia-pacific/crime-legal/taiwan-nvidia-chip-smuggling/
- Keelung prosecutors’ account of the Nvidia whitelist and site inspection requirement: https://mlq.ai/news/taiwan-indicts-nine-in-alleged-nvidia-b300-server-diversion-to-china/
- Reuters, via CNBC, on the unpublished Entity List designations: https://www.cnbc.com/2026/06/17/us-deepseek-blacklist-cxmt-national-security-risks-.html
Jeff Newman Law is a national whistleblower law firm that handles SEC whistleblower cases and False Claims Act cases. The firm can be reached at www.JeffNewmanLaw.com or at 617-823-3217