📊 Full opportunity report: AI Sovereignty Certification: What The 24% Rule Tells Us About Validity on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The 24% ownership rule in France’s SecNumCloud framework is a key measure of legal sovereignty for cloud providers. It emphasizes ownership control over security practices, impacting how providers qualify for sovereignty certification. This rule is shaping European AI and cloud governance moving forward.
France’s SecNumCloud framework introduces a unique ownership cap of 24% on foreign control, marking a significant shift in AI sovereignty certification. This rule directly impacts which providers can qualify for sovereignty status by emphasizing legal ownership over traditional security measures, making it a critical development for European data governance.
SecNumCloud, created by France’s ANSSI, is a qualification rather than a certification, requiring providers to meet strict criteria including EU legal domicile, EU-only data storage, and audited key custody. The most distinctive element is the ownership rule: companies not based in the EU must hold less than 24% ownership individually or 39% collectively to qualify. This arithmetic-based ownership threshold is designed to ensure legal sovereignty and prevent foreign control from overriding local jurisdiction.
As of mid-2026, about ten providers, including OVHcloud and Scaleway, have obtained SecNumCloud status, with more in the pipeline. The rule is mandatory for hosting sensitive French public-sector data and is expected to extend to critical infrastructure sectors across Europe. The framework aims to strengthen legal sovereignty by restricting foreign influence through ownership caps, not just technical controls.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Implications of the 24% Ownership Cap for European Data Sovereignty
The 24% ownership rule fundamentally shifts the focus from traditional security certifications to ownership and control as the key determinants of sovereignty. This approach aims to prevent foreign governments from exerting legal influence over European cloud and AI providers. It also sets a precedent that could influence other jurisdictions, emphasizing ownership structure as a legal safeguard. For European industries handling sensitive data, this means increased assurance of legal independence from non-EU laws, especially the CLOUD Act.
However, the rule also complicates provider eligibility, potentially limiting the pool of qualified vendors and increasing operational complexity. It underscores the importance of ownership transparency and may accelerate the development of EU-based or EU-controlled cloud providers, shaping the future landscape of AI and cloud sovereignty.
EU data sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How the 24% Control Rule Fits into European Sovereignty Frameworks
The SecNumCloud scheme is part of France’s broader strategy to secure legal sovereignty over cloud services, especially in sensitive sectors like health, finance, and energy. Unlike typical security certifications such as ISO 27001 or C5, which verify operational practices, SecNumCloud explicitly tests ownership control through the 24% rule. This approach was introduced in 2023 and is now a core requirement for providers serving the French public sector and potentially other critical European markets.
Historically, providers like AWS and Microsoft have held certifications like C5 but remain subject to U.S. jurisdiction, including the CLOUD Act. The ownership cap aims to address this by restricting foreign influence, effectively creating a form of legal firewall based on ownership structure rather than just technical controls. The rule reflects a broader European push toward data sovereignty and legal independence from non-EU jurisdictions.
“The ownership cap ensures that foreign control does not undermine the legal sovereignty of French and European data infrastructure.”
— ANSSI spokesperson

Klein Tools Hard Hat, Non-Vented Cap Style, Padded, Self-Wicking Odor-Resistant Sweatband, Tested up to 20kV
Safety hard hat has patent-pending accessory mounts on front and back ensure Klein Headlamps attach securely and precisely,…
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Unclear Aspects of the 24% Ownership Regulation
While the ownership cap is clearly defined, its practical enforcement and impact on provider operations remain uncertain. It is not yet clear how many existing providers will be able to restructure ownership to meet the 24% limit or how this will influence the competitive landscape. Additionally, the long-term implications for non-EU companies and their ability to participate in European markets are still evolving. The extent to which other European countries will adopt similar measures is also uncertain.
cloud provider ownership structure analysis
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps for Compliance and Market Impact
Providers aiming for SecNumCloud certification will need to review their ownership structures and possibly restructure to meet the 24% limit. As of mid-2026, more providers are expected to seek certification, and the regulation may expand to other sectors. European regulators and industry stakeholders will likely monitor the implementation closely, potentially leading to further refinements or new standards emphasizing ownership control. The ongoing development of EU-wide sovereignty policies suggests a continued emphasis on legal independence as a core criterion.
cybersecurity audit software for sovereignty
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the main purpose of the 24% ownership rule?
The rule aims to ensure legal sovereignty by limiting foreign control over providers, preventing foreign governments from exerting influence through ownership structures.
Does holding a certification mean a provider is immune from non-EU laws?
No. Certifications like SecNumCloud focus on operational security and ownership control but do not eliminate legal jurisdiction or extraterritorial laws like the CLOUD Act.
How does the 24% rule affect existing providers like AWS or Microsoft?
They would need to restructure ownership to comply with the cap if they seek to qualify for sovereignty certification in France or other EU countries adopting similar standards.
Is this ownership cap likely to be adopted outside France?
It is uncertain. While other European countries may consider similar sovereignty measures, the 24% rule is currently specific to France’s SecNumCloud framework.
Source: ThorstenMeyerAI.com