📊 Full opportunity report: The 24% Rule Reveals Why Many AI Sovereign Cloud Certifications Are Misleading on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The 24% ownership cap in France’s SecNumCloud framework exposes that many so-called sovereign cloud certifications do not guarantee legal sovereignty. This challenges claims of independence and raises questions about the true security and control of data in European clouds.
The 24% ownership threshold in France’s SecNumCloud framework is now a key measure for legal sovereignty, revealing that many cloud providers with European certifications are still subject to foreign jurisdiction, despite claims of sovereignty. This development questions the validity of many so-called ‘sovereign’ cloud certifications and their ability to guarantee legal control over data.
SecNumCloud, created by France’s ANSSI, is a government-issued qualification that emphasizes legal sovereignty, including data location and ownership. Its defining feature is the 24% ownership cap on foreign-controlled companies, which aims to prevent non-EU entities from exerting legal influence over cloud providers hosting sensitive data. As of mid-2026, only about a dozen providers have achieved this qualification, including OVHcloud and Outscale, with several more in progress.
Many providers, especially US-based hyperscalers like AWS, Microsoft, and Google, cannot meet the sovereignty requirements directly because they are subject to US laws such as the CLOUD Act. To circumvent this, some have established joint ventures or control arrangements where foreign ownership is below the threshold, allowing them to claim compliance with SecNumCloud standards while remaining under foreign jurisdiction. This approach has led to skepticism about whether certifications truly guarantee sovereignty or merely demonstrate adherence to security practices.
Meanwhile, certifications like BSI C5 focus on security controls and operational practices but do not address legal jurisdiction, which remains a critical factor in sovereignty. For example, AWS’s European Sovereign Cloud, certified under BSI C5, is physically and logically separate within the EU but still subject to US law because Amazon remains an American company.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Implications of the 24% Ownership Limit for Cloud Sovereignty
The 24% ownership rule fundamentally challenges the notion that certifications alone guarantee legal sovereignty over data. It reveals that many providers can still be influenced or compelled by foreign governments, despite holding European or security certifications. This impacts organizations in regulated industries, such as healthcare and finance, that rely on these certifications to meet legal and compliance standards. The development underscores the importance of ownership structures and control rights in assessing true sovereignty, beyond security controls and operational standards.
European sovereign cloud certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Understanding the Limits of Certification-Based Sovereignty Claims
European frameworks like SecNumCloud were introduced to enhance legal sovereignty, especially for sensitive public-sector data. Created by France’s ANSSI in 2016, SecNumCloud emphasizes ownership and jurisdiction, with a strict ownership cap as a core criterion. This contrasts with other certifications such as ISO 27001, SOC 2, and BSI C5, which mainly verify security practices but do not address legal control or jurisdiction.
Many US cloud providers have adapted by creating control structures that meet the ownership threshold, often through joint ventures or controlling entities, allowing them to claim compliance with sovereignty standards. However, critics argue that these arrangements do not eliminate the influence of foreign law, raising questions about the effectiveness of current certification schemes in guaranteeing true legal independence.
“The 24% ownership rule is a simple but powerful arithmetic test that reveals whether a provider is truly sovereign or merely claiming it through complex control arrangements.”
— Thorsten Meyer, AI compliance expert
Unresolved Questions About Certification Effectiveness
It remains unclear how many providers are actively using control structures to circumvent the ownership cap without truly achieving sovereignty. There is also uncertainty about how regulators will enforce or verify compliance with the 24% rule in practice, especially across complex corporate structures. Additionally, the broader impact of these arrangements on data security and legal risk is still being evaluated.
Next Steps in Certification and Sovereignty Enforcement
Regulators in France and across Europe are expected to increase scrutiny of control arrangements and ownership structures, possibly refining the rules or introducing new audits focused on legal sovereignty. Several providers are likely to pursue certification strategies that emphasize ownership compliance, while organizations will need to reassess their control and legal risks when selecting cloud services. Further developments will clarify whether the 24% rule becomes a de facto standard for sovereignty or remains a challenge for compliance.
Key Questions
Does holding a SecNumCloud certification guarantee legal sovereignty?
No, it primarily indicates compliance with security and operational standards. The ownership cap is the key measure for sovereignty, but even then, arrangements can be complex.
Can foreign-owned providers still claim sovereignty under European standards?
Yes, if they keep foreign ownership below 24% and control structures are designed accordingly, but this does not necessarily mean they are immune from foreign jurisdiction or law.
Why is the ownership threshold important?
The 24% ownership limit is a clear, arithmetic test for legal sovereignty, preventing foreign governments from exerting control through ownership alone.
Are certifications like BSI C5 or ISO 27001 sufficient for sovereignty?
No, these mainly verify security practices and operational controls but do not address legal jurisdiction or ownership control.
What future developments might affect sovereignty certifications?
Regulatory bodies may tighten rules around control structures, and more rigorous audits could be introduced to verify actual legal independence of cloud providers.
Source: ThorstenMeyerAI.com