📊 Full opportunity report: Understanding AI Sovereignty Certification Failures With The 24% Rule on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership cap in France’s SecNumCloud framework aims to ensure legal sovereignty over AI and data services. Several providers struggle to meet this requirement, revealing complexities in sovereignty certification and US tech exclusion. The development highlights ongoing debates over jurisdiction and control in European AI regulation.

France’s SecNumCloud framework enforces a 24% ownership cap on foreign control to ensure legal sovereignty over cloud and AI services. Several providers, including major European and non-European firms, are struggling to meet this requirement, highlighting the framework’s impact on US tech companies and European sovereignty efforts. This development matters because it directly influences the control and legal jurisdiction of AI and data services operating within Europe.

The SecNumCloud qualification, created by France’s ANSSI, is a government-backed standard that includes a 24% ownership rule. This rule restricts individual foreign ownership to 24% and collective ownership to 39% to guarantee legal sovereignty over data and services hosted in France. It is not a typical certification but a qualification backed by government authority, requiring compliance with specific legal and ownership criteria.

As of mid-2026, only about ten providers have obtained an active SecNumCloud qualification, including OVHcloud, Outscale (Dassault), and Scaleway. Major US tech firms like Amazon and Microsoft are unable to meet the ownership caps directly because they are subject to US laws, such as the CLOUD Act. To circumvent this, US-based providers have formed joint ventures with European firms, such as Thales and Capgemini, where control is shifted to European entities to satisfy the ownership limits.

The 24% rule is a particularly strict and arithmetic-based control measure, making it difficult for large, globally integrated corporations to qualify directly. This has led to a strategic shift among US tech giants, who are establishing European-controlled entities that meet the ownership thresholds, thus attempting to maintain access to the European market while complying with sovereignty requirements.

At a glance
analysisWhen: ongoing; developments as of mid-2026
The developmentThe article examines the challenges faced by cloud and AI providers in meeting France’s 24% ownership rule under SecNumCloud, emphasizing its implications for sovereignty certification and US tech involvement.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Control Limit for European AI Sovereignty

The 24% ownership cap is a critical component of France’s SecNumCloud framework, designed to safeguard legal sovereignty over data and AI services. It effectively excludes US tech giants from directly qualifying, pushing them to create European-controlled joint ventures. This shift could reshape the landscape of cloud and AI services in Europe, fostering more localized control but also complicating partnerships and operational structures. The rule underscores Europe’s push for sovereignty and control over critical digital infrastructure amid ongoing geopolitical tensions.

Amazon

European cloud sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on France’s Sovereignty Framework and the 24% Rule

France’s SecNumCloud was introduced in 2016 by ANSSI, aiming to establish a sovereign cloud standard that combines technical, organizational, operational, and legal requirements. Unlike typical certifications, SecNumCloud is a qualification that involves government oversight, including legal controls such as data storage within the EU, audited key custody, and immunity from non-EU extraterritorial laws. The 24% ownership rule was added in the latest version (3.2) to address sovereignty concerns, specifically targeting foreign control by limiting individual and collective foreign ownership in qualifying providers.

Major providers like AWS, Microsoft, and Google cannot meet the ownership thresholds directly due to their US-based ownership structures and legal obligations under US law. Consequently, they are establishing European joint ventures to comply with the rule, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu project, where control is shifted to European entities.

“SecNumCloud is designed to guarantee French sovereignty over sensitive data, and the ownership rule is central to this objective.”

— Anssi spokesperson

Unresolved Challenges in Meeting the 24% Control Limit

It remains unclear how many existing providers will successfully restructure their ownership to meet the 24% limit without losing operational control or market access. The long-term viability of US tech firms establishing fully compliant European-controlled entities is still uncertain, as legal, operational, and political factors evolve. Additionally, the precise impact on market competition and service availability in Europe is still developing, with some providers in the process of restructuring or delaying certification.

Next Steps for Providers and European Sovereignty Policies

In the coming months, more providers are expected to pursue European-controlled joint ventures to meet the ownership threshold. Regulatory authorities will likely tighten oversight and enforce compliance, especially among firms handling sensitive public-sector data. Additionally, the European Commission and national agencies may introduce further legal and technical standards to reinforce sovereignty and control, shaping the future landscape of cloud and AI services in Europe.

Key Questions

Why is the 24% ownership rule so strict?

The 24% ownership cap is designed to ensure European legal sovereignty by limiting foreign control, especially from US-based companies subject to extraterritorial laws like the CLOUD Act.

Can US tech companies still operate in Europe under this framework?

Yes, but they must establish European-controlled joint ventures where control is shifted to European entities to meet the ownership criteria, as direct qualification is often impossible due to US law.

Does meeting the ownership cap guarantee sovereignty?

No, the ownership rule is a control test; it does not automatically ensure immunity from legal jurisdiction or other sovereignty issues.

What are the implications for European AI development?

The rule encourages local control and may foster more European-led AI initiatives, but it could also complicate international partnerships and limit access to global cloud infrastructure.

Source: ThorstenMeyerAI.com

You May Also Like

Why Multi‑Tenant GPUs Fail in Production (and How to Fix It)

Navigating the pitfalls of multi-tenant GPUs reveals common failure points and solutions, but understanding the full picture is essential for success.

The Secret to Stable MoE: Routing Collapse, Load Balance, and Monitoring

Master the key techniques to prevent routing collapse and ensure stable MoE models—discover how proper load balancing and monitoring can make all the difference.