Understanding The 24% Rule In AI Sovereignty Certifications

📊 Full opportunity report: Understanding The 24% Rule In AI Sovereignty Certifications on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

France’s SecNumCloud certification includes a unique ownership rule limiting foreign control to 24%. This rule aims to ensure legal sovereignty over data and AI services within the EU, but its practical impact and global adoption remain evolving. This article clarifies what the rule entails and its significance for providers and users.

France’s national cybersecurity agency, ANSSI, has implemented a new sovereignty criterion within its SecNumCloud framework, involving a 24% ownership cap on foreign control of cloud and AI providers. This rule is designed to ensure that providers operating in France and the EU are under European legal sovereignty, addressing concerns over extraterritorial laws and foreign influence. The rule is now a key factor for vendors seeking SecNumCloud qualification, which is mandatory for hosting sensitive public-sector data in France.

The 24% ownership rule is part of the SecNumCloud qualification, created by ANSSI in 2016 and now in its latest version 3.2. It requires that capital and voting rights held by entities outside the EU do not exceed 24% individually, or 39% collectively. This arithmetic threshold is the first of its kind, directly addressing ownership and control rather than just technical security practices.

SecNumCloud is not a traditional certification but a qualification issued after an audit by authorized evaluators, backed by the French government. It mandates EU data domicile, EU-only data storage, audited key custody, and immunity from non-EU extraterritorial law. As of mid-2026, approximately nine to ten providers, including OVHcloud and Scaleway, hold an active qualification, with more in progress. The framework is now a legal requirement for hosting sensitive French public-sector data and is expected to expand to other critical sectors.

At a glance
reportWhen: developing as of mid-2026, with active…
The developmentFrance’s SecNumCloud framework enforces a 24% ownership cap to guarantee legal sovereignty over cloud and AI services, a unique approach in European cybersecurity standards.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Ownership Cap for Data Sovereignty

The 24% ownership rule represents a novel approach to legal sovereignty in cloud and AI services within Europe. It shifts the focus from technical security controls to ownership and control, directly addressing concerns over foreign influence and extraterritorial laws. For providers, complying with this rule means restructuring ownership or control mechanisms, often involving complex corporate arrangements. For users, it offers a higher assurance that data stored and processed within these providers remains under European jurisdiction, reducing risks associated with laws like the CLOUD Act. As the framework gains prominence, it could influence global standards on sovereignty and data control, especially in sensitive sectors like health, energy, and finance.

CompTIA Security+ Certification Kit: Exam SY0-701 (Sybex Study Guide)

CompTIA Security+ Certification Kit: Exam SY0-701 (Sybex Study Guide)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background and Development of the Sovereignty Control Measures

The concept of sovereignty in cloud computing has gained prominence amid increasing concerns over foreign legal influence and data localization. France’s SecNumCloud initiative, launched in 2016, was designed to create a government-backed security qualification that goes beyond technical controls to address legal jurisdiction. The critical innovation was the ownership cap, introduced in version 3.2, which limits foreign control to 24%. This development follows broader European efforts to assert digital sovereignty and reduce dependence on non-EU providers, especially American hyperscalers. While other frameworks like BSI C5 focus on security controls, SecNumCloud emphasizes control and ownership as the key to sovereignty.

“The qualification commits the French State to the security level of the service and ensures control remains within the EU jurisdiction.”

— Anssi official, speaking on SecNumCloud

Data Transformation for the AI Era: Building the Intelligence Fabric of the Enterprise. The 6x6 Blueprint for Data Sovereignty and Trusted Analytics. ... series for enterprise transformation)

Data Transformation for the AI Era: Building the Intelligence Fabric of the Enterprise. The 6×6 Blueprint for Data Sovereignty and Trusted Analytics. … series for enterprise transformation)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About the 24% Control Limit

It remains unclear how widely the 24% ownership rule will be adopted outside France or whether other European countries will implement similar controls. The practical enforceability of the cap, especially in complex corporate structures, is also still being evaluated. Additionally, the impact on US-based hyperscalers and their ability to qualify under the framework is uncertain, given their corporate ownership structures and the possibility of strategic control arrangements. The long-term influence of this regulation on global data sovereignty standards is still developing, and legal challenges or adaptations may arise.

LOCALIZED AI AND DATA SOVEREIGNTY: Building Private Large Language Model Clusters with On-Premises Control and Global Data Governance Standards (The Sovereign Cloud Architect Series)

LOCALIZED AI AND DATA SOVEREIGNTY: Building Private Large Language Model Clusters with On-Premises Control and Global Data Governance Standards (The Sovereign Cloud Architect Series)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Providers and Policy Development

As of mid-2026, more providers are expected to seek SecNumCloud qualification, navigating the ownership restrictions. The French government is likely to refine enforcement and possibly expand the scope to other sectors. International providers will need to adapt their ownership structures to meet the 24% cap if they aim to access the French and broader European markets. Meanwhile, other European nations may consider similar sovereignty measures, potentially leading to a patchwork of regulations. Monitoring the evolution of these controls and their legal interpretations will be crucial for stakeholders.

The Cybersecurity Body of Knowledge (Security, Audit and Leadership Series)

The Cybersecurity Body of Knowledge (Security, Audit and Leadership Series)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the main purpose of the 24% ownership rule?

The rule aims to ensure European legal sovereignty over cloud and AI services by limiting foreign control, reducing reliance on non-EU laws and extraterritorial influence.

Does holding a SecNumCloud qualification mean a provider is immune from US laws?

No. The qualification guarantees compliance with French legal sovereignty requirements but does not exempt providers from US laws like the CLOUD Act if they are US-based or controlled by US entities.

How does the ownership cap affect US tech giants operating in Europe?

US companies must structure ownership or control arrangements to keep foreign control below 24%, which may involve joint ventures or other corporate strategies to meet the requirement.

Is this ownership rule unique to France?

Yes, it is a specific feature of France’s SecNumCloud framework, but it could influence broader European policies on data sovereignty and control in the future.

Source: ThorstenMeyerAI.com

You May Also Like

What Investors Really Look for in 2026

In 2026, you’ll want to focus on investments that combine innovation with…

The European Bet: How Mistral, Aleph Alpha, and Black Forest Labs Are Playing a Different Game

European AI firms Mistral, Aleph Alpha, and Black Forest Labs are positioning for the EU AI Act enforcement, emphasizing compliance and sovereignty over frontier capabilities.

Apple Quietly Acquires Start‑Up That Could Kill the Iphone

Just when you thought the iPhone’s reign was secure, Apple’s secret acquisition hints at revolutionary changes ahead—discover what could challenge its dominance.

The European Union: Rules First, Cushion Always

EU emphasizes regulation and social protections over ownership in managing AI and economic transition, with key policies set for 2026 implementation.