📊 Full opportunity report: Understanding AI Sovereignty Certification Failures With The 24% Rule on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The 24% ownership cap in France’s SecNumCloud framework aims to ensure legal sovereignty over AI and data services. Several providers struggle to meet this requirement, revealing complexities in sovereignty certification and US tech exclusion. The development highlights ongoing debates over jurisdiction and control in European AI regulation.
France’s SecNumCloud framework enforces a 24% ownership cap on foreign control to ensure legal sovereignty over cloud and AI services. Several providers, including major European and non-European firms, are struggling to meet this requirement, highlighting the framework’s impact on US tech companies and European sovereignty efforts. This development matters because it directly influences the control and legal jurisdiction of AI and data services operating within Europe.
The SecNumCloud qualification, created by France’s ANSSI, is a government-backed standard that includes a 24% ownership rule. This rule restricts individual foreign ownership to 24% and collective ownership to 39% to guarantee legal sovereignty over data and services hosted in France. It is not a typical certification but a qualification backed by government authority, requiring compliance with specific legal and ownership criteria.
As of mid-2026, only about ten providers have obtained an active SecNumCloud qualification, including OVHcloud, Outscale (Dassault), and Scaleway. Major US tech firms like Amazon and Microsoft are unable to meet the ownership caps directly because they are subject to US laws, such as the CLOUD Act. To circumvent this, US-based providers have formed joint ventures with European firms, such as Thales and Capgemini, where control is shifted to European entities to satisfy the ownership limits.
The 24% rule is a particularly strict and arithmetic-based control measure, making it difficult for large, globally integrated corporations to qualify directly. This has led to a strategic shift among US tech giants, who are establishing European-controlled entities that meet the ownership thresholds, thus attempting to maintain access to the European market while complying with sovereignty requirements.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Implications of the 24% Control Limit for European AI Sovereignty
The 24% ownership cap is a critical component of France’s SecNumCloud framework, designed to safeguard legal sovereignty over data and AI services. It effectively excludes US tech giants from directly qualifying, pushing them to create European-controlled joint ventures. This shift could reshape the landscape of cloud and AI services in Europe, fostering more localized control but also complicating partnerships and operational structures. The rule underscores Europe’s push for sovereignty and control over critical digital infrastructure amid ongoing geopolitical tensions.
European cloud sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Background on France’s Sovereignty Framework and the 24% Rule
France’s SecNumCloud was introduced in 2016 by ANSSI, aiming to establish a sovereign cloud standard that combines technical, organizational, operational, and legal requirements. Unlike typical certifications, SecNumCloud is a qualification that involves government oversight, including legal controls such as data storage within the EU, audited key custody, and immunity from non-EU extraterritorial laws. The 24% ownership rule was added in the latest version (3.2) to address sovereignty concerns, specifically targeting foreign control by limiting individual and collective foreign ownership in qualifying providers.
Major providers like AWS, Microsoft, and Google cannot meet the ownership thresholds directly due to their US-based ownership structures and legal obligations under US law. Consequently, they are establishing European joint ventures to comply with the rule, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu project, where control is shifted to European entities.
“SecNumCloud is designed to guarantee French sovereignty over sensitive data, and the ownership rule is central to this objective.”
— Anssi spokesperson
Unresolved Challenges in Meeting the 24% Control Limit
It remains unclear how many existing providers will successfully restructure their ownership to meet the 24% limit without losing operational control or market access. The long-term viability of US tech firms establishing fully compliant European-controlled entities is still uncertain, as legal, operational, and political factors evolve. Additionally, the precise impact on market competition and service availability in Europe is still developing, with some providers in the process of restructuring or delaying certification.
Next Steps for Providers and European Sovereignty Policies
In the coming months, more providers are expected to pursue European-controlled joint ventures to meet the ownership threshold. Regulatory authorities will likely tighten oversight and enforce compliance, especially among firms handling sensitive public-sector data. Additionally, the European Commission and national agencies may introduce further legal and technical standards to reinforce sovereignty and control, shaping the future landscape of cloud and AI services in Europe.
Key Questions
Why is the 24% ownership rule so strict?
The 24% ownership cap is designed to ensure European legal sovereignty by limiting foreign control, especially from US-based companies subject to extraterritorial laws like the CLOUD Act.
Can US tech companies still operate in Europe under this framework?
Yes, but they must establish European-controlled joint ventures where control is shifted to European entities to meet the ownership criteria, as direct qualification is often impossible due to US law.
Does meeting the ownership cap guarantee sovereignty?
No, the ownership rule is a control test; it does not automatically ensure immunity from legal jurisdiction or other sovereignty issues.
What are the implications for European AI development?
The rule encourages local control and may foster more European-led AI initiatives, but it could also complicate international partnerships and limit access to global cloud infrastructure.
Source: ThorstenMeyerAI.com