Siemens now sits at both ends of the emerging AI conflict.

At one end, the company is part of Europe's attempt to reduce dependence on any single artificial-intelligence provider. Reuters reported in June that Siemens was already using a mix of American, European and Chinese models, including DeepSeek and Alibaba's Qwen, as it sought flexibility, cost discipline and continuity.

At the other end, U.S. agencies have warned of an active cyber threat involving Siemens S7 programmable logic controllers used across water, energy, manufacturing, agriculture and other critical sectors. The warning followed a broader campaign in which Iranian-affiliated actors were observed targeting exposed operational-technology systems.

The coincidence is strategically important. But it must be interpreted with discipline.

There is no public evidence that Siemens' use of Chinese AI models enabled these attacks, that a Chinese model was embedded in the targeted controllers, or that artificial intelligence was the mechanism by which Iranian-affiliated actors gained access. Treating temporal proximity as proof would weaken the analysis.

The real connection is structural.

The same global architecture that makes AI more accessible, cheaper and harder to block is now meeting an industrial architecture built for reliability, long equipment life and physical control. Their intersection creates both resilience and risk.

1. The non-blockadable layer has arrived

The AI order is fragmenting into two simultaneous systems.

The first is the frontier layer: concentrated, capital-intensive and controlled by a small number of American and Chinese firms. It depends on advanced chips, hyperscale data centers, restricted model access and enormous energy consumption.

The second is the non-blockadable layer: open-weight or locally deployable models, multiple providers, regional clouds, industrial systems and lower-cost intelligence that can continue operating when access to a preferred vendor is restricted.

For legitimate companies, this layer is a continuity strategy. If a proprietary model can be withdrawn by a government or provider, an enterprise that relies on it exclusively has accepted a geopolitical single point of failure. Multi-model architecture and local deployment reduce that dependency.

For sanctioned states, proxies and criminal actors, the same diffusion lowers the entry cost for reconnaissance, translation, code adaptation, social engineering and operational planning. The technology does not create the intent. It compresses the time and expertise needed to act on it.

That is the central ambiguity of non-blockadable AI: the features that make it resilient for the defender can also make it available to the attacker.

2. Critical infrastructure is the asymmetric battlefield

The United States is extraordinarily difficult to challenge conventionally. Its nuclear deterrent, naval capacity, aerospace power, intelligence system and financial reach make frontal confrontation irrational for most adversaries.

The response is asymmetric.

Water utilities, power grids, factories, food systems, pipelines and transport networks are attractive because they connect digital access to physical consequence. Many depend on operational-technology equipment designed to function for decades. Some remain exposed to the internet, use weak authentication, run legacy software or cannot be patched without interrupting essential services.

A programmable logic controller is not merely an information system. It can open a valve, stop a pump, alter pressure, interrupt a production line or affect a safety process. This is where cyber risk becomes continuity risk.

The strategic objective of an asymmetric campaign does not have to be catastrophic destruction. Repeated low-cost intrusions can force expensive defense, generate public anxiety, test response procedures, expose weak municipalities and fragment attention across thousands of local targets.

3. The Siemens paradox

Siemens is not paradoxical because it uses Chinese AI while Chinese or Iranian actors attack its products. That causal chain has not been demonstrated.

The paradox is that Siemens represents both sides of the continuity problem.

It is building the diversified, model-agnostic industrial AI stack that companies need in a fragmented geopolitical environment.

Its controllers and automation systems are part of the physical infrastructure that adversaries may target precisely because modern societies depend on them.

Vendor diversification at the cognitive layer does not automatically create resilience at the physical layer. An enterprise can avoid dependence on one AI provider and still remain exposed through an unsegmented network, an internet-facing controller, a weak identity system, an unpatched engineering workstation or an operator without visibility into abnormal behavior.

Conversely, the presence of a vulnerable or targeted device does not make its manufacturer equivalent to the threat actor. Industrial resilience depends on the entire operating environment: the vendor, integrator, asset owner, network architecture, maintenance process, security controls and public response capacity.

4. What must be separated analytically

Four layers must not be collapsed into one another:

The model layer: which AI systems an enterprise uses and where they are hosted.

The software layer: engineering tools, applications, digital twins and operational interfaces.

The control layer: programmable logic controllers, sensors, actuators and safety systems.

The threat layer: the actor, access vector, capability, objective and command structure behind an intrusion.

A connection among these layers is possible and should be investigated. It cannot be assumed. Serious strategic intelligence distinguishes evidence, hypothesis and implication.

What is already established is enough to matter: major industrial companies are diversifying away from single-provider AI dependence at the same moment that adversaries are intensifying pressure on distributed critical infrastructure.

5. The implication for AI resilience

AI resilience is not model performance under ideal conditions. It is the capacity to preserve essential functions when models, networks, energy, suppliers, jurisdictions or physical assets become unavailable or compromised.

For industrial systems, that requires:

Asset visibility across IT and operational technology.

Network segmentation and the removal of unnecessary internet exposure.

Strong identity, secure remote access and rapid credential rotation.

Patchability, compensating controls and tested manual fallback.

Multi-model and multi-provider AI architecture without uncontrolled data movement.

Continuous monitoring that understands physical process behavior, not only conventional malware signatures.

Governance that separates experimentation from systems capable of producing physical consequences.

This is also why AI resilience is investable. The companies that matter are not only those building models. They include the firms that secure grids, water systems, industrial networks, semiconductors, communications, energy supply and operational continuity.

6. The discipline required for an AI Resilience ETF

A serious AI Resilience ETF cannot treat every industrial or cybersecurity company as resilient by definition. It must audit both capability and exposure.

The relevant questions are concrete:

Does the company occupy a difficult-to-replace position in critical infrastructure?

Can its systems operate across providers and jurisdictions?

Does it reduce single points of failure, or create new ones?

Can its products be patched, segmented, monitored and recovered under stress?

Is security designed into the product lifecycle, or transferred to the customer after deployment?

Does the balance sheet support long investment cycles and crisis response?

Siemens belongs inside this analytical map because it connects artificial intelligence to the physical economy at global scale. That makes it strategically relevant. It does not exempt the company from scrutiny. It makes the scrutiny more important.

7. The next AI conflict will be physical

The next phase of AI competition will not remain inside data centers or model benchmarks. It will move through pumps, substations, ports, factories, satellites, cooling systems and the networks that connect them.

The decisive actors will not be only the organizations that create intelligence. They will be the organizations that keep intelligence, infrastructure and institutions functioning when the system is attacked.

The Siemens paradox is therefore not a story about one company or one cyber alert. It is a preview of the order now emerging: intelligence is becoming more distributed at the exact moment that the physical systems beneath it are becoming more contested.

The non-blockadable layer increases autonomy. Critical infrastructure turns that autonomy into real power. Resilience is what determines whether the combination becomes an advantage or a vulnerability.