TL;DR
The 24% ownership rule in France’s SecNumCloud framework is a key measure of legal sovereignty for cloud providers. It emphasizes ownership control over security practices, impacting how providers qualify for sovereignty certification. This rule is shaping European AI and cloud governance moving forward.
France’s SecNumCloud framework introduces a unique ownership cap of 24% on foreign control, marking a significant shift in AI sovereignty certification. This rule directly impacts which providers can qualify for sovereignty status by emphasizing legal ownership over traditional security measures, making it a critical development for European data governance.
SecNumCloud, created by France’s ANSSI, is a qualification rather than a certification, requiring providers to meet strict criteria including EU legal domicile, EU-only data storage, and audited key custody. The most distinctive element is the ownership rule: companies not based in the EU must hold less than 24% ownership individually or 39% collectively to qualify. This arithmetic-based ownership threshold is designed to ensure legal sovereignty and prevent foreign control from overriding local jurisdiction.
As of mid-2026, about ten providers, including OVHcloud and Scaleway, have obtained SecNumCloud status, with more in the pipeline. The rule is mandatory for hosting sensitive French public-sector data and is expected to extend to critical infrastructure sectors across Europe. The framework aims to strengthen legal sovereignty by restricting foreign influence through ownership caps, not just technical controls.
Implications of the 24% Ownership Cap for European Data Sovereignty
The 24% ownership rule fundamentally shifts the focus from traditional security certifications to ownership and control as the key determinants of sovereignty. This approach aims to prevent foreign governments from exerting legal influence over European cloud and AI providers. It also sets a precedent that could influence other jurisdictions, emphasizing ownership structure as a legal safeguard. For European industries handling sensitive data, this means increased assurance of legal independence from non-EU laws, especially the CLOUD Act.
However, the rule also complicates provider eligibility, potentially limiting the pool of qualified vendors and increasing operational complexity. It underscores the importance of ownership transparency and may accelerate the development of EU-based or EU-controlled cloud providers, shaping the future landscape of AI and cloud sovereignty.
EU cloud sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How the 24% Control Rule Fits into European Sovereignty Frameworks
The SecNumCloud scheme is part of France’s broader strategy to secure legal sovereignty over cloud services, especially in sensitive sectors like health, finance, and energy. Unlike typical security certifications such as ISO 27001 or C5, which verify operational practices, SecNumCloud explicitly tests ownership control through the 24% rule. This approach was introduced in 2023 and is now a core requirement for providers serving the French public sector and potentially other critical European markets.
Historically, providers like AWS and Microsoft have held certifications like C5 but remain subject to U.S. jurisdiction, including the CLOUD Act. The ownership cap aims to address this by restricting foreign influence, effectively creating a form of legal firewall based on ownership structure rather than just technical controls. The rule reflects a broader European push toward data sovereignty and legal independence from non-EU jurisdictions.
“The ownership cap ensures that foreign control does not undermine the legal sovereignty of French and European data infrastructure.”
— ANSSI spokesperson
ownership control cloud security products
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Unclear Aspects of the 24% Ownership Regulation
While the ownership cap is clearly defined, its practical enforcement and impact on provider operations remain uncertain. It is not yet clear how many existing providers will be able to restructure ownership to meet the 24% limit or how this will influence the competitive landscape. Additionally, the long-term implications for non-EU companies and their ability to participate in European markets are still evolving. The extent to which other European countries will adopt similar measures is also uncertain.
EU data sovereignty compliance tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps for Compliance and Market Impact
Providers aiming for SecNumCloud certification will need to review their ownership structures and possibly restructure to meet the 24% limit. As of mid-2026, more providers are expected to seek certification, and the regulation may expand to other sectors. European regulators and industry stakeholders will likely monitor the implementation closely, potentially leading to further refinements or new standards emphasizing ownership control. The ongoing development of EU-wide sovereignty policies suggests a continued emphasis on legal independence as a core criterion.
cloud provider ownership transparency solutions
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the main purpose of the 24% ownership rule?
The rule aims to ensure legal sovereignty by limiting foreign control over providers, preventing foreign governments from exerting influence through ownership structures.
Does holding a certification mean a provider is immune from non-EU laws?
No. Certifications like SecNumCloud focus on operational security and ownership control but do not eliminate legal jurisdiction or extraterritorial laws like the CLOUD Act.
How does the 24% rule affect existing providers like AWS or Microsoft?
They would need to restructure ownership to comply with the cap if they seek to qualify for sovereignty certification in France or other EU countries adopting similar standards.
Is this ownership cap likely to be adopted outside France?
It is uncertain. While other European countries may consider similar sovereignty measures, the 24% rule is currently specific to France’s SecNumCloud framework.
Source: ThorstenMeyerAI.com