📊 Full opportunity report: How The 24% Rule Exposes Flaws In AI Sovereignty Testing on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership rule in France’s SecNumCloud framework exposes fundamental flaws in sovereignty testing for AI and cloud providers. While certifications verify security practices, they do not guarantee legal control, raising questions about data sovereignty in European regulation.

The 24% ownership cap in France’s SecNumCloud framework is now a key criterion for demonstrating legal sovereignty of cloud providers, exposing a significant flaw in current testing methods for AI and cloud data control.

SecNumCloud, developed by France’s national cybersecurity agency ANSSI, includes a unique rule: foreign ownership exceeding 24% of voting rights disqualifies a provider from certification. This ownership threshold is expressed as an arithmetic check, making it a straightforward, checkable criterion for sovereignty.

While traditional security certifications like ISO 27001, SOC 2, and BSI C5 verify operational security practices, they do not address legal jurisdiction or ownership control. SecNumCloud’s ownership rule aims to fill this gap by explicitly testing legal sovereignty, but its practical implications reveal limitations in current frameworks.

As of mid-2026, only about a dozen providers have achieved SecNumCloud qualification, including OVHcloud and Outscale, with several more in progress. This certification is mandatory for hosting sensitive French public-sector data and is being pushed for critical infrastructure under EU regulations.

At a glance
reportWhen: developing, as of mid-2026
The developmentThe 24% ownership rule in France’s SecNumCloud framework reveals critical limitations in assessing legal sovereignty of cloud providers, impacting AI and data security standards.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Ownership Cap in Sovereignty Testing

The 24% ownership rule exposes a fundamental flaw in how sovereignty is tested for cloud and AI providers. Certifications that verify security practices do not address who ultimately controls the data or the provider’s legal jurisdiction. This gap means that companies can hold certifications but still be subject to foreign laws, such as the US CLOUD Act, if ownership exceeds the threshold.

For European regulators and clients, this raises concerns about the true sovereignty of data stored and processed within certified providers. It also complicates procurement decisions, as organizations must now consider ownership structures alongside security standards.

The rule’s arithmetic simplicity makes it a powerful, transparent test, but it also reveals that current certification schemes inadequately address legal control, which is critical for data sovereignty in sensitive sectors like health, finance, and energy.

Amazon

ISO 27001 security certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Sovereignty Frameworks and Certification Limitations

France’s SecNumCloud was introduced in 2016 and updated to version 3.2, incorporating strict legal sovereignty requirements, including EU data residency and immunity from non-EU law. Its unique ownership cap is designed to prevent foreign legal reach, especially from the US, by limiting foreign ownership to below 24%.

Other frameworks, such as Germany’s BSI C5, focus on operational controls and transparency but do not explicitly test legal sovereignty or control. BSI C5 requires disclosure of jurisdiction but does not impose ownership limits, leaving residual risk if a provider is under foreign control.

US hyperscalers like AWS are ineligible for SecNumCloud in native form due to ownership and control restrictions but have created joint ventures with controlled ownership structures to meet the 24% threshold, such as S3NS and Bleu, which are operated by non-US entities but still subject to US law.

“SecNumCloud’s ownership cap is designed to ensure that providers operating within France are legally controlled within the EU, but it does not eliminate all jurisdictional risks.”

— ANSSI spokesperson

Amazon

cloud data sovereignty testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Remaining Questions About Sovereignty and Certification Effectiveness

It is still unclear how effectively the 24% rule prevents foreign legal influence, especially as providers create ownership structures to circumvent the cap. The real-world legal and operational risks posed by foreign control remain difficult to quantify.

Additionally, the broader impact of this rule on global cloud and AI providers, and whether it will be adopted or adapted by other European countries, is still developing.

Amazon

AI sovereignty compliance software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Sovereignty Testing and Certification Standards

Regulators are expected to refine and expand sovereignty testing criteria, potentially incorporating more nuanced legal control measures beyond ownership caps. Providers will likely continue to develop ownership structures to meet these requirements, raising ongoing compliance challenges.

Further analysis and case studies will emerge as more providers achieve SecNumCloud certification, revealing the practical effectiveness and limitations of the 24% rule in protecting European data sovereignty.

Amazon

European cloud security certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the significance of the 24% ownership rule in SecNumCloud?

The 24% ownership rule provides a simple, arithmetic test for legal sovereignty, aiming to prevent foreign control over providers handling sensitive EU data. However, it also exposes gaps in current certification schemes that only verify security practices, not legal control.

Does certification guarantee that a provider is immune from foreign laws?

No. Certifications like SecNumCloud verify operational security and ownership limits but do not eliminate the risk of foreign jurisdictional influence, especially if ownership structures are designed to circumvent the rules.

Why are US hyperscalers creating joint ventures with controlled ownership?

To meet the 24% ownership cap and qualify for European sovereignty certifications like SecNumCloud, US hyperscalers are establishing joint ventures with non-US entities, though they remain subject to US law.

Will other European countries adopt similar sovereignty testing frameworks?

It is still uncertain, but the success and limitations of France’s SecNumCloud may influence broader European policy development on data sovereignty and cloud certification standards.

What are the practical implications for companies choosing cloud providers?

Organizations must consider not only security certifications but also ownership structures and jurisdictional controls when selecting providers for sensitive data, especially in regulated sectors.

Source: ThorstenMeyerAI.com

You May Also Like

Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

A hidden tracker for Anthropic’s Claude AI has been uncovered, raising concerns about surveillance despite the company’s public anti-surveillance policies.

White-collar professional services. The Tier 1 displacement.

Major firms reduce graduate intake and test AI tools, signaling significant displacement in white-collar professional services, with long-term pipeline impacts.

Avoiding Clickbait: Ethical Title Practices

Honest and ethical title practices build trust, but discovering the key to avoiding clickbait can transform your content strategy—are you ready to learn more?

The rails. Why European agentic commerce is co-defined by two converging regimes.

European agentic commerce is being shaped by two converging regulatory regimes—PSD3/PSR and the AI Act—creating a complex, statutory infrastructure that differs from the US model.