📊 Full opportunity report: Dissecting The 24% Rule: The Truth About AI Sovereignty Testing on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The 24% ownership rule is a key component of France’s SecNumCloud framework, testing foreign control over cloud providers. This article explains what it means for AI sovereignty and provider compliance.
France’s national cybersecurity agency, ANSSI, enforces a 24% ownership cap on foreign companies controlling cloud providers seeking SecNumCloud certification. This rule is a core part of the framework designed to guarantee legal sovereignty over data, making it a critical factor for AI and cloud vendors operating in Europe. The development matters because it directly influences foreign ownership structures and provider eligibility for the highest security standards in France and potentially across Europe.
The SecNumCloud qualification, issued by ANSSI, is not a traditional certification but a government-backed qualification that requires compliance with strict legal and operational standards, including data sovereignty. Created in 2016 and now at version 3.2, it involves a comprehensive audit process and mandates that providers operate within the EU, store data locally, and be immune from non-EU extraterritorial laws.
The 24% ownership rule is a straightforward arithmetic limit on foreign control, specifying that individual foreign investors cannot hold more than 24% of voting rights, and combined foreign ownership cannot exceed 39%. This rule aims to prevent foreign governments or companies from exerting undue influence or legal reach over critical cloud infrastructure. Providers like OVHcloud and Scaleway have achieved this qualification, which is mandatory for hosting sensitive French public-sector data and other critical services.
Major US-based hyperscalers like AWS remain subject to US law, even if they hold a C5 attestation or operate within the EU. To circumvent ownership restrictions, US firms have created joint ventures or control structures that keep foreign ownership below the threshold, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu, with Thales holding operational control in the former.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Implications of the 24% Ownership Cap for Cloud Providers
The 24% ownership rule fundamentally shapes the landscape of European cloud sovereignty. It acts as a practical test of legal control rather than security controls, forcing foreign companies to restructure ownership to qualify for secure cloud services in France. This impacts US tech giants and other non-EU providers, who must navigate complex ownership arrangements to comply.
For AI providers, especially those handling sensitive data, this rule influences market access and compliance strategies. It underscores the importance of ownership and control structures over technical security measures alone, shifting the focus toward legal sovereignty. The debate over sovereignty testing is likely to intensify as other European countries consider similar frameworks, and the 24% rule may become a benchmark for sovereignty in AI and cloud services.
As an affiliate, we earn on qualifying purchases.
European Sovereignty Testing and the Role of Ownership Limits
France’s SecNumCloud framework is part of a broader European effort to ensure digital sovereignty amid geopolitical tensions and data privacy concerns. Unlike traditional security certifications like ISO 27001 or BSI C5, SecNumCloud emphasizes legal control, with the 24% ownership cap serving as a tangible arithmetic test of sovereignty.
Created in 2016, SecNumCloud has evolved to include strict legal requirements, such as EU data residency, audited key custody, and immunity from non-EU laws. While other frameworks like BSI C5 focus on technical controls and transparency about jurisdiction, SecNumCloud’s ownership rule directly limits foreign influence, making it a unique and influential standard.
As of mid-2026, around ten providers hold the qualification, with additional firms in the pipeline. This reflects a growing trend among European nations to enforce sovereignty through ownership controls, especially for critical infrastructure and sensitive AI applications.
“The 24% ownership rule is the defining arithmetic test of sovereignty in France’s SecNumCloud framework, directly linking control to legal and ownership structures.”
— Thorsten Meyer
Unresolved Questions About the 24% Control Limit
It is still unclear how the 24% ownership rule will evolve as European regulators expand sovereignty testing to other sectors and countries. The framework’s reliance on ownership arithmetic raises questions about how complex ownership structures, such as layered holding companies or control via subsidiaries, will be interpreted and enforced. Additionally, the long-term impact on US and non-EU providers remains uncertain, especially regarding how they will adapt their corporate structures to meet sovereignty requirements.
Next Steps for Providers and Regulators in Sovereignty Testing
Moving forward, more providers are expected to pursue SecNumCloud qualification or equivalent sovereignty standards across Europe. Regulators are likely to refine enforcement mechanisms and clarify how ownership structures are assessed, especially as geopolitical tensions influence data sovereignty policies. The ongoing development of joint ventures and control arrangements will be critical for non-EU firms aiming to access the European market, while European authorities may expand sovereignty tests to other critical infrastructure sectors.
Key Questions
Why does the 24% ownership rule matter for AI providers?
The rule determines whether foreign AI companies can operate cloud services in France under sovereignty standards, affecting market access and compliance strategies.
Can US-based companies qualify for SecNumCloud?
Yes, but they must structure ownership controls carefully, such as through joint ventures or control arrangements that keep foreign ownership below 24%.
Is the ownership cap a legal requirement or just a guideline?
It is a strict legal requirement embedded in the SecNumCloud qualification process, backed by government oversight and audits.
How does this rule compare to other sovereignty standards like BSI C5?
While BSI C5 focuses on technical controls and transparency about jurisdiction, the 24% rule explicitly limits foreign control, making it a unique sovereignty test.
What are the risks for providers who cannot meet the ownership limit?
They may be barred from offering services for sensitive public-sector data or critical infrastructure in France, limiting their market opportunities.
Source: ThorstenMeyerAI.com