AI Sovereignty Certification: What The 24% Rule Tells Us About Validity

📊 Full opportunity report: AI Sovereignty Certification: What The 24% Rule Tells Us About Validity on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership rule in France’s SecNumCloud framework is a key measure of legal sovereignty for cloud providers. It emphasizes ownership control over security practices, impacting how providers qualify for sovereignty certification. This rule is shaping European AI and cloud governance moving forward.

France’s SecNumCloud framework introduces a unique ownership cap of 24% on foreign control, marking a significant shift in AI sovereignty certification. This rule directly impacts which providers can qualify for sovereignty status by emphasizing legal ownership over traditional security measures, making it a critical development for European data governance.

SecNumCloud, created by France’s ANSSI, is a qualification rather than a certification, requiring providers to meet strict criteria including EU legal domicile, EU-only data storage, and audited key custody. The most distinctive element is the ownership rule: companies not based in the EU must hold less than 24% ownership individually or 39% collectively to qualify. This arithmetic-based ownership threshold is designed to ensure legal sovereignty and prevent foreign control from overriding local jurisdiction.

As of mid-2026, about ten providers, including OVHcloud and Scaleway, have obtained SecNumCloud status, with more in the pipeline. The rule is mandatory for hosting sensitive French public-sector data and is expected to extend to critical infrastructure sectors across Europe. The framework aims to strengthen legal sovereignty by restricting foreign influence through ownership caps, not just technical controls.

At a glance
analysisWhen: developing; as of mid-2026, the rule is…
The developmentThe article analyzes the implications of the 24% ownership cap in France’s SecNumCloud framework for AI sovereignty and data control.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Ownership Cap for European Data Sovereignty

The 24% ownership rule fundamentally shifts the focus from traditional security certifications to ownership and control as the key determinants of sovereignty. This approach aims to prevent foreign governments from exerting legal influence over European cloud and AI providers. It also sets a precedent that could influence other jurisdictions, emphasizing ownership structure as a legal safeguard. For European industries handling sensitive data, this means increased assurance of legal independence from non-EU laws, especially the CLOUD Act.

However, the rule also complicates provider eligibility, potentially limiting the pool of qualified vendors and increasing operational complexity. It underscores the importance of ownership transparency and may accelerate the development of EU-based or EU-controlled cloud providers, shaping the future landscape of AI and cloud sovereignty.

Amazon

EU data sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How the 24% Control Rule Fits into European Sovereignty Frameworks

The SecNumCloud scheme is part of France’s broader strategy to secure legal sovereignty over cloud services, especially in sensitive sectors like health, finance, and energy. Unlike typical security certifications such as ISO 27001 or C5, which verify operational practices, SecNumCloud explicitly tests ownership control through the 24% rule. This approach was introduced in 2023 and is now a core requirement for providers serving the French public sector and potentially other critical European markets.

Historically, providers like AWS and Microsoft have held certifications like C5 but remain subject to U.S. jurisdiction, including the CLOUD Act. The ownership cap aims to address this by restricting foreign influence, effectively creating a form of legal firewall based on ownership structure rather than just technical controls. The rule reflects a broader European push toward data sovereignty and legal independence from non-EU jurisdictions.

“The ownership cap ensures that foreign control does not undermine the legal sovereignty of French and European data infrastructure.”

— ANSSI spokesperson

Klein Tools Hard Hat, Non-Vented Cap Style, Padded, Self-Wicking Odor-Resistant Sweatband, Tested up to 20kV

Klein Tools Hard Hat, Non-Vented Cap Style, Padded, Self-Wicking Odor-Resistant Sweatband, Tested up to 20kV

Safety hard hat has patent-pending accessory mounts on front and back ensure Klein Headlamps attach securely and precisely,…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Aspects of the 24% Ownership Regulation

While the ownership cap is clearly defined, its practical enforcement and impact on provider operations remain uncertain. It is not yet clear how many existing providers will be able to restructure ownership to meet the 24% limit or how this will influence the competitive landscape. Additionally, the long-term implications for non-EU companies and their ability to participate in European markets are still evolving. The extent to which other European countries will adopt similar measures is also uncertain.

Amazon

cloud provider ownership structure analysis

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Compliance and Market Impact

Providers aiming for SecNumCloud certification will need to review their ownership structures and possibly restructure to meet the 24% limit. As of mid-2026, more providers are expected to seek certification, and the regulation may expand to other sectors. European regulators and industry stakeholders will likely monitor the implementation closely, potentially leading to further refinements or new standards emphasizing ownership control. The ongoing development of EU-wide sovereignty policies suggests a continued emphasis on legal independence as a core criterion.

Amazon

cybersecurity audit software for sovereignty

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the main purpose of the 24% ownership rule?

The rule aims to ensure legal sovereignty by limiting foreign control over providers, preventing foreign governments from exerting influence through ownership structures.

Does holding a certification mean a provider is immune from non-EU laws?

No. Certifications like SecNumCloud focus on operational security and ownership control but do not eliminate legal jurisdiction or extraterritorial laws like the CLOUD Act.

How does the 24% rule affect existing providers like AWS or Microsoft?

They would need to restructure ownership to comply with the cap if they seek to qualify for sovereignty certification in France or other EU countries adopting similar standards.

Is this ownership cap likely to be adopted outside France?

It is uncertain. While other European countries may consider similar sovereignty measures, the 24% rule is currently specific to France’s SecNumCloud framework.

Source: ThorstenMeyerAI.com

This content is for general information only and is not financial, tax or legal advice. Consult a qualified professional for decisions about your money.
You May Also Like

The Atlas. What the framework is.

The Post-Labor Transition Atlas is a new empirically grounded framework analyzing AI labor displacement, policy responses, and structural alternatives as of 2026.

Three Days at the Frontier: Washington Suspends Fable 5 and Mythos 5

The US government has suspended access to Anthropic’s Fable 5 and Mythos 5 models amid national-security concerns following a jailbreak demonstration.

Apple Silicon’s Quiet Memory Advantage

Apple Silicon chips offer a unique, cost-effective way to run large AI models with shared memory, bypassing traditional GPU VRAM limits. Here’s what you need to know.

BofA Technician Sees a ‘Three-Wave Correction’ in S&P 500 Index

A Bank of America technician forecasts a three-wave correction in the S&P 500 index, signaling potential volatility ahead. Details are still developing.