The 24% Rule Reveals Why Many AI Sovereign Cloud Certifications Are Misleading
KIDieser Beitrag wurde mit Unterstützung künstlicher Intelligenz (KI) erstellt.

📊 Full opportunity report: The 24% Rule Reveals Why Many AI Sovereign Cloud Certifications Are Misleading on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership cap in France’s SecNumCloud framework exposes that many so-called sovereign cloud certifications do not guarantee legal sovereignty. This challenges claims of independence and raises questions about the true security and control of data in European clouds.

The 24% ownership threshold in France’s SecNumCloud framework is now a key measure for legal sovereignty, revealing that many cloud providers with European certifications are still subject to foreign jurisdiction, despite claims of sovereignty. This development questions the validity of many so-called ‘sovereign’ cloud certifications and their ability to guarantee legal control over data.

SecNumCloud, created by France’s ANSSI, is a government-issued qualification that emphasizes legal sovereignty, including data location and ownership. Its defining feature is the 24% ownership cap on foreign-controlled companies, which aims to prevent non-EU entities from exerting legal influence over cloud providers hosting sensitive data. As of mid-2026, only about a dozen providers have achieved this qualification, including OVHcloud and Outscale, with several more in progress.

Many providers, especially US-based hyperscalers like AWS, Microsoft, and Google, cannot meet the sovereignty requirements directly because they are subject to US laws such as the CLOUD Act. To circumvent this, some have established joint ventures or control arrangements where foreign ownership is below the threshold, allowing them to claim compliance with SecNumCloud standards while remaining under foreign jurisdiction. This approach has led to skepticism about whether certifications truly guarantee sovereignty or merely demonstrate adherence to security practices.

Meanwhile, certifications like BSI C5 focus on security controls and operational practices but do not address legal jurisdiction, which remains a critical factor in sovereignty. For example, AWS’s European Sovereign Cloud, certified under BSI C5, is physically and logically separate within the EU but still subject to US law because Amazon remains an American company.

At a glance
reportWhen: developing; as of mid-2026, the rule is…
The developmentThe 24% ownership rule in France’s SecNumCloud framework reveals that many cloud providers with European certifications remain subject to foreign jurisdiction, questioning their sovereignty claims.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Ownership Limit for Cloud Sovereignty

The 24% ownership rule fundamentally challenges the notion that certifications alone guarantee legal sovereignty over data. It reveals that many providers can still be influenced or compelled by foreign governments, despite holding European or security certifications. This impacts organizations in regulated industries, such as healthcare and finance, that rely on these certifications to meet legal and compliance standards. The development underscores the importance of ownership structures and control rights in assessing true sovereignty, beyond security controls and operational standards.

Amazon

European sovereign cloud certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Understanding the Limits of Certification-Based Sovereignty Claims

European frameworks like SecNumCloud were introduced to enhance legal sovereignty, especially for sensitive public-sector data. Created by France’s ANSSI in 2016, SecNumCloud emphasizes ownership and jurisdiction, with a strict ownership cap as a core criterion. This contrasts with other certifications such as ISO 27001, SOC 2, and BSI C5, which mainly verify security practices but do not address legal control or jurisdiction.

Many US cloud providers have adapted by creating control structures that meet the ownership threshold, often through joint ventures or controlling entities, allowing them to claim compliance with sovereignty standards. However, critics argue that these arrangements do not eliminate the influence of foreign law, raising questions about the effectiveness of current certification schemes in guaranteeing true legal independence.

“The 24% ownership rule is a simple but powerful arithmetic test that reveals whether a provider is truly sovereign or merely claiming it through complex control arrangements.”

— Thorsten Meyer, AI compliance expert

Unresolved Questions About Certification Effectiveness

It remains unclear how many providers are actively using control structures to circumvent the ownership cap without truly achieving sovereignty. There is also uncertainty about how regulators will enforce or verify compliance with the 24% rule in practice, especially across complex corporate structures. Additionally, the broader impact of these arrangements on data security and legal risk is still being evaluated.

Next Steps in Certification and Sovereignty Enforcement

Regulators in France and across Europe are expected to increase scrutiny of control arrangements and ownership structures, possibly refining the rules or introducing new audits focused on legal sovereignty. Several providers are likely to pursue certification strategies that emphasize ownership compliance, while organizations will need to reassess their control and legal risks when selecting cloud services. Further developments will clarify whether the 24% rule becomes a de facto standard for sovereignty or remains a challenge for compliance.

Key Questions

No, it primarily indicates compliance with security and operational standards. The ownership cap is the key measure for sovereignty, but even then, arrangements can be complex.

Can foreign-owned providers still claim sovereignty under European standards?

Yes, if they keep foreign ownership below 24% and control structures are designed accordingly, but this does not necessarily mean they are immune from foreign jurisdiction or law.

Why is the ownership threshold important?

The 24% ownership limit is a clear, arithmetic test for legal sovereignty, preventing foreign governments from exerting control through ownership alone.

Are certifications like BSI C5 or ISO 27001 sufficient for sovereignty?

No, these mainly verify security practices and operational controls but do not address legal jurisdiction or ownership control.

What future developments might affect sovereignty certifications?

Regulatory bodies may tighten rules around control structures, and more rigorous audits could be introduced to verify actual legal independence of cloud providers.

Source: ThorstenMeyerAI.com

This content is for general information only and is not financial, tax or legal advice. Consult a qualified professional for decisions about your money.
You May Also Like

Jack Clark Says It Out Loud — Reading the Co-Founder’s 60%/2028 Estimate on Automated AI R&D

Anthropic’s co-founder Jack Clark publicly estimates a 60% probability that autonomous AI system development could occur by 2028, signaling significant policy implications.

Could Three AI Models Be Creating A Single Narrative For All?

Analysis of how overlapping AI models may be homogenizing societal interpretation, risking reduced diversity in understanding events and markets.

Signal: The Agent Bottleneck Moved — It’s Not the Models Anymore, It’s the Plumbing

New insights reveal infrastructure and integration, not models, now limit enterprise AI agent deployment, favoring small operators with full-stack ownership.

The stake. Why the answer to automation is broad-based ownership, not a bigger transfer.

Thorsten Meyer argues that the response to AI-driven automation should focus on expanding ownership of capital, not increasing transfer payments or retraining efforts.