TL;DR
The 24% ownership rule is a key component of France’s SecNumCloud framework, testing foreign control over cloud providers. This article explains what it means for AI sovereignty and provider compliance.
France’s national cybersecurity agency, ANSSI, enforces a 24% ownership cap on foreign companies controlling cloud providers seeking SecNumCloud certification. This rule is a core part of the framework designed to guarantee legal sovereignty over data, making it a critical factor for AI and cloud vendors operating in Europe. The development matters because it directly influences foreign ownership structures and provider eligibility for the highest security standards in France and potentially across Europe.
The SecNumCloud qualification, issued by ANSSI, is not a traditional certification but a government-backed qualification that requires compliance with strict legal and operational standards, including data sovereignty. Created in 2016 and now at version 3.2, it involves a comprehensive audit process and mandates that providers operate within the EU, store data locally, and be immune from non-EU extraterritorial laws.
The 24% ownership rule is a straightforward arithmetic limit on foreign control, specifying that individual foreign investors cannot hold more than 24% of voting rights, and combined foreign ownership cannot exceed 39%. This rule aims to prevent foreign governments or companies from exerting undue influence or legal reach over critical cloud infrastructure. Providers like OVHcloud and Scaleway have achieved this qualification, which is mandatory for hosting sensitive French public-sector data and other critical services.
Major US-based hyperscalers like AWS remain subject to US law, even if they hold a C5 attestation or operate within the EU. To circumvent ownership restrictions, US firms have created joint ventures or control structures that keep foreign ownership below the threshold, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu, with Thales holding operational control in the former.
Implications of the 24% Ownership Cap for Cloud Providers
The 24% ownership rule fundamentally shapes the landscape of European cloud sovereignty. It acts as a practical test of legal control rather than security controls, forcing foreign companies to restructure ownership to qualify for secure cloud services in France. This impacts US tech giants and other non-EU providers, who must navigate complex ownership arrangements to comply.
For AI providers, especially those handling sensitive data, this rule influences market access and compliance strategies. It underscores the importance of ownership and control structures over technical security measures alone, shifting the focus toward legal sovereignty. The debate over sovereignty testing is likely to intensify as other European countries consider similar frameworks, and the 24% rule may become a benchmark for sovereignty in AI and cloud services.
As an affiliate, we earn on qualifying purchases.
European Sovereignty Testing and the Role of Ownership Limits
France’s SecNumCloud framework is part of a broader European effort to ensure digital sovereignty amid geopolitical tensions and data privacy concerns. Unlike traditional security certifications like ISO 27001 or BSI C5, SecNumCloud emphasizes legal control, with the 24% ownership cap serving as a tangible arithmetic test of sovereignty.
Created in 2016, SecNumCloud has evolved to include strict legal requirements, such as EU data residency, audited key custody, and immunity from non-EU laws. While other frameworks like BSI C5 focus on technical controls and transparency about jurisdiction, SecNumCloud’s ownership rule directly limits foreign influence, making it a unique and influential standard.
As of mid-2026, around ten providers hold the qualification, with additional firms in the pipeline. This reflects a growing trend among European nations to enforce sovereignty through ownership controls, especially for critical infrastructure and sensitive AI applications.
“The 24% ownership rule is the defining arithmetic test of sovereignty in France’s SecNumCloud framework, directly linking control to legal and ownership structures.”
— Thorsten Meyer
Unresolved Questions About the 24% Control Limit
It is still unclear how the 24% ownership rule will evolve as European regulators expand sovereignty testing to other sectors and countries. The framework’s reliance on ownership arithmetic raises questions about how complex ownership structures, such as layered holding companies or control via subsidiaries, will be interpreted and enforced. Additionally, the long-term impact on US and non-EU providers remains uncertain, especially regarding how they will adapt their corporate structures to meet sovereignty requirements.
Next Steps for Providers and Regulators in Sovereignty Testing
Moving forward, more providers are expected to pursue SecNumCloud qualification or equivalent sovereignty standards across Europe. Regulators are likely to refine enforcement mechanisms and clarify how ownership structures are assessed, especially as geopolitical tensions influence data sovereignty policies. The ongoing development of joint ventures and control arrangements will be critical for non-EU firms aiming to access the European market, while European authorities may expand sovereignty tests to other critical infrastructure sectors.
Key Questions
Why does the 24% ownership rule matter for AI providers?
The rule determines whether foreign AI companies can operate cloud services in France under sovereignty standards, affecting market access and compliance strategies.
Can US-based companies qualify for SecNumCloud?
Yes, but they must structure ownership controls carefully, such as through joint ventures or control arrangements that keep foreign ownership below 24%.
Is the ownership cap a legal requirement or just a guideline?
It is a strict legal requirement embedded in the SecNumCloud qualification process, backed by government oversight and audits.
How does this rule compare to other sovereignty standards like BSI C5?
While BSI C5 focuses on technical controls and transparency about jurisdiction, the 24% rule explicitly limits foreign control, making it a unique sovereignty test.
What are the risks for providers who cannot meet the ownership limit?
They may be barred from offering services for sensitive public-sector data or critical infrastructure in France, limiting their market opportunities.
Source: ThorstenMeyerAI.com