Evaluating AI Sovereignty Certifications: Lessons From The 24% Rule
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The SecNumCloud framework introduces a unique ownership cap—24%—to assess legal sovereignty over cloud and AI services. This rule emphasizes control and jurisdiction, impacting providers’ compliance strategies and market positioning.

France’s national cybersecurity agency, ANSSI, has implemented a new sovereignty test within its SecNumCloud qualification, requiring providers to ensure that foreign ownership does not exceed 24%. This rule aims to guarantee legal control over data and services hosted within the European Union, marking a significant shift in how sovereignty is measured in cloud and AI certifications.

SecNumCloud is a government-issued qualification that builds on ISO 27001 but introduces a novel ownership cap—24%—to assess control over cloud providers. Unlike traditional security certifications like ISO 27001 or BSI C5, which verify operational practices, SecNumCloud explicitly tests ownership and jurisdiction. Providers must demonstrate that no single foreign entity holds more than 24% of voting rights, a checkable, arithmetic measure derived from the company’s cap table. As of mid-2026, about ten providers, including OVHcloud and Outscale, hold an active SecNumCloud qualification, with more in the pipeline. This certification is mandatory for hosting sensitive French public-sector data and is being promoted for critical infrastructure across the EU.

Additionally, the certification requires compliance with EU data storage, audited key custody, and immunity from non-EU extraterritorial laws. The 24% ownership rule is considered extremely challenging to meet, especially for US-based providers, who often have significant foreign ownership. To circumvent this, US hyperscalers like AWS have established joint ventures with European companies—such as Thales and Capgemini—that hold operational control, thus complying with the ownership cap while maintaining US legal ties.

At a glance
analysisWhen: developing as of mid-2026
The developmentFrance’s SecNumCloud certification enforces a 24% ownership rule to ensure legal sovereignty over cloud and AI services, challenging traditional security certifications.

Implications of the 24% Ownership Cap for Cloud Providers

The 24% ownership rule embedded in SecNumCloud represents a fundamental shift in how sovereignty is measured—moving beyond traditional security controls to focus on ownership and control. For European public sector and critical infrastructure, this rule aims to prevent foreign legal reach, particularly from non-EU jurisdictions like the US. It creates a high barrier for providers, especially US-based firms, who must restructure ownership or establish joint ventures to meet the requirement. This development could reshape the competitive landscape, favoring European providers and forcing US giants to adapt their control structures if they wish to access the EU market.

Moreover, the emphasis on legal sovereignty over security practices underscores a broader trend: certifications are increasingly used as legal tools to enforce jurisdictional control, not just operational security. This could influence how companies approach compliance and how regulators define sovereignty in digital services.

Amazon

EU data sovereignty cloud certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on European Sovereignty Certifications

European regulators have long emphasized data sovereignty and control, but traditional certifications like ISO 27001, SOC 2, and BSI C5 focus on operational security practices without addressing jurisdictional control. The introduction of SecNumCloud in 2016 by ANSSI marked a shift toward integrating legal sovereignty into certification schemes. The key innovation was the ownership cap—a clear, arithmetic measure that directly tests control over the provider’s ownership structure. This approach responds to concerns about foreign influence and extraterritorial laws, especially in the context of US cloud providers operating within the EU.

As of 2026, the adoption of SecNumCloud is expanding, driven by legal requirements for sensitive data and critical infrastructure. The framework’s design also influences other European standards and could serve as a model for future sovereignty assessments, especially in AI and emerging technologies.

“The 24% ownership rule is a game-changer because it quantifies control in a way that’s checkable and enforceable, unlike traditional security certifications.”

— Thorsten Meyer, AI compliance expert

Amazon

ISO 27001 cybersecurity certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Remaining Questions About the 24% Sovereignty Rule

It is still unclear how strictly regulators will enforce the ownership cap across different types of providers and whether exceptions or transitional arrangements will be made for existing US-based cloud giants. The long-term impact on US providers’ ability to operate within the EU depends on how strictly joint ventures and control structures are scrutinized. Additionally, the precise legal implications for providers that fall just above the threshold remain to be clarified, as well as how the rule will evolve with market and geopolitical shifts.

Amazon

European cloud service provider

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Providers and Regulators in EU Cloud Sovereignty

Providers aiming for SecNumCloud certification will need to review their ownership structures and consider restructuring or establishing joint ventures to meet the 24% ownership limit. US firms, in particular, may accelerate the formation of European-controlled entities or joint ventures to comply. Meanwhile, regulators are expected to refine enforcement practices and possibly extend the sovereignty test to other sectors and technologies, including AI. The upcoming years will reveal how this framework influences market dynamics and international cloud service strategies within Europe.

Amazon

secure cloud storage for government

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the significance of the 24% ownership rule in SecNumCloud?

The 24% ownership rule is a quantitative measure designed to ensure legal sovereignty by limiting foreign ownership, thereby reducing external legal influence over cloud services hosted within the EU.

How does SecNumCloud differ from traditional security certifications?

Unlike certifications like ISO 27001 or BSI C5, which verify operational security practices, SecNumCloud explicitly tests ownership and jurisdictional control through a measurable, arithmetic ownership cap.

Can US cloud providers meet the SecNumCloud requirements?

Yes, but they often need to establish joint ventures or restructure ownership so that no single foreign entity exceeds 24% ownership, as seen with AWS’s European Sovereign Cloud and other partnerships.

Will the 24% rule impact US companies’ ability to operate in Europe?

Potentially, yes. US firms may need to adapt their ownership and control structures to comply, which could influence their market strategies and operational models within the EU.

Is the ownership cap likely to be adopted outside France?

While currently specific to France’s SecNumCloud, the concept of quantifiable sovereignty measures could influence broader European or international standards in the future.

Source: ThorstenMeyerAI.com

You May Also Like

The Safe Rating Detail That Matters More Than Exterior Size

Just focusing on exterior size can be misleading; discover the safety rating detail that truly determines your vehicle’s protection.

Signal: Europe Is Actually Shopping for Its Palantir Exit

European countries are actively seeking alternatives to Palantir for military and intelligence systems, with contracts and testing underway within two years.

The AI Strategy Behind Ukraine’s Digital Resistance To Russia’s Amazon

Ukraine’s digital resistance targets Russian e-commerce and logistics platforms using AI and cyber tactics, disrupting supply chains and military procurement.

VigilSAR: The Object That Isn’t Transmitting

VigilSAR identifies radar-detected vessels with no transponder signals, enhancing maritime awareness in all weather conditions. Key capabilities demonstrated using Sentinel-1 data.