Dissecting The 24% Rule: The Truth About AI Sovereignty Testing

📊 Full opportunity report: Dissecting The 24% Rule: The Truth About AI Sovereignty Testing on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership rule is a key component of France’s SecNumCloud framework, testing foreign control over cloud providers. This article explains what it means for AI sovereignty and provider compliance.

France’s national cybersecurity agency, ANSSI, enforces a 24% ownership cap on foreign companies controlling cloud providers seeking SecNumCloud certification. This rule is a core part of the framework designed to guarantee legal sovereignty over data, making it a critical factor for AI and cloud vendors operating in Europe. The development matters because it directly influences foreign ownership structures and provider eligibility for the highest security standards in France and potentially across Europe.

The SecNumCloud qualification, issued by ANSSI, is not a traditional certification but a government-backed qualification that requires compliance with strict legal and operational standards, including data sovereignty. Created in 2016 and now at version 3.2, it involves a comprehensive audit process and mandates that providers operate within the EU, store data locally, and be immune from non-EU extraterritorial laws.

The 24% ownership rule is a straightforward arithmetic limit on foreign control, specifying that individual foreign investors cannot hold more than 24% of voting rights, and combined foreign ownership cannot exceed 39%. This rule aims to prevent foreign governments or companies from exerting undue influence or legal reach over critical cloud infrastructure. Providers like OVHcloud and Scaleway have achieved this qualification, which is mandatory for hosting sensitive French public-sector data and other critical services.

Major US-based hyperscalers like AWS remain subject to US law, even if they hold a C5 attestation or operate within the EU. To circumvent ownership restrictions, US firms have created joint ventures or control structures that keep foreign ownership below the threshold, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu, with Thales holding operational control in the former.

At a glance
analysisWhen: developing, as of mid-2026
The developmentFrance’s SecNumCloud framework enforces a 24% ownership cap to ensure legal sovereignty over cloud providers, impacting how foreign firms operate in Europe.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Ownership Cap for Cloud Providers

The 24% ownership rule fundamentally shapes the landscape of European cloud sovereignty. It acts as a practical test of legal control rather than security controls, forcing foreign companies to restructure ownership to qualify for secure cloud services in France. This impacts US tech giants and other non-EU providers, who must navigate complex ownership arrangements to comply.

For AI providers, especially those handling sensitive data, this rule influences market access and compliance strategies. It underscores the importance of ownership and control structures over technical security measures alone, shifting the focus toward legal sovereignty. The debate over sovereignty testing is likely to intensify as other European countries consider similar frameworks, and the 24% rule may become a benchmark for sovereignty in AI and cloud services.

Amazon

cloud security compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Sovereignty Testing and the Role of Ownership Limits

France’s SecNumCloud framework is part of a broader European effort to ensure digital sovereignty amid geopolitical tensions and data privacy concerns. Unlike traditional security certifications like ISO 27001 or BSI C5, SecNumCloud emphasizes legal control, with the 24% ownership cap serving as a tangible arithmetic test of sovereignty.

Created in 2016, SecNumCloud has evolved to include strict legal requirements, such as EU data residency, audited key custody, and immunity from non-EU laws. While other frameworks like BSI C5 focus on technical controls and transparency about jurisdiction, SecNumCloud’s ownership rule directly limits foreign influence, making it a unique and influential standard.

As of mid-2026, around ten providers hold the qualification, with additional firms in the pipeline. This reflects a growing trend among European nations to enforce sovereignty through ownership controls, especially for critical infrastructure and sensitive AI applications.

“The 24% ownership rule is the defining arithmetic test of sovereignty in France’s SecNumCloud framework, directly linking control to legal and ownership structures.”

— Thorsten Meyer

Unresolved Questions About the 24% Control Limit

It is still unclear how the 24% ownership rule will evolve as European regulators expand sovereignty testing to other sectors and countries. The framework’s reliance on ownership arithmetic raises questions about how complex ownership structures, such as layered holding companies or control via subsidiaries, will be interpreted and enforced. Additionally, the long-term impact on US and non-EU providers remains uncertain, especially regarding how they will adapt their corporate structures to meet sovereignty requirements.

Next Steps for Providers and Regulators in Sovereignty Testing

Moving forward, more providers are expected to pursue SecNumCloud qualification or equivalent sovereignty standards across Europe. Regulators are likely to refine enforcement mechanisms and clarify how ownership structures are assessed, especially as geopolitical tensions influence data sovereignty policies. The ongoing development of joint ventures and control arrangements will be critical for non-EU firms aiming to access the European market, while European authorities may expand sovereignty tests to other critical infrastructure sectors.

Key Questions

Why does the 24% ownership rule matter for AI providers?

The rule determines whether foreign AI companies can operate cloud services in France under sovereignty standards, affecting market access and compliance strategies.

Can US-based companies qualify for SecNumCloud?

Yes, but they must structure ownership controls carefully, such as through joint ventures or control arrangements that keep foreign ownership below 24%.

It is a strict legal requirement embedded in the SecNumCloud qualification process, backed by government oversight and audits.

How does this rule compare to other sovereignty standards like BSI C5?

While BSI C5 focuses on technical controls and transparency about jurisdiction, the 24% rule explicitly limits foreign control, making it a unique sovereignty test.

What are the risks for providers who cannot meet the ownership limit?

They may be barred from offering services for sensitive public-sector data or critical infrastructure in France, limiting their market opportunities.

Source: ThorstenMeyerAI.com

You May Also Like

Data processing agreement tracker for micro SaaS teams

A new DPA tracker tailored for founder-led micro SaaS teams is being tested to streamline vendor and customer data paperwork management, addressing a growing privacy compliance need.

I Wasn’t Allowed Prompting ChatGPT During My Chalk Talk: This Is Discrimination (2025)

A teacher alleges she was barred from prompting ChatGPT during her presentation, raising concerns about discrimination and AI access fairness.

Sovereignty Is a Pipe, Not a Passport

Mistral’s AI models highlight that sovereignty depends on data flow infrastructure, not just company nationality or server location.

Briefro: A Document That Tells The Truth

Briefro introduces a new AI tool that generates documents bound to real data, running locally to ensure privacy and accuracy, now shipping its v1.