AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The 24% ownership threshold in France’s SecNumCloud framework reveals fundamental challenges in verifying AI sovereignty. This development questions the effectiveness of current sovereignty tests and their practical implications for cloud providers.

France’s national cybersecurity agency, ANSSI, has implemented a 24% ownership cap as part of its SecNumCloud framework, a key sovereignty requirement for cloud providers hosting sensitive data within the EU. This rule directly tests the ownership and control of foreign companies over cloud services, marking a significant development in sovereignty verification. The rule’s practical impact is already influencing provider strategies and regulatory compliance, making it a critical point of focus for European and international cloud providers.

The 24% ownership threshold in the SecNumCloud framework is designed to ensure legal sovereignty by limiting foreign ownership of companies controlling cloud infrastructure. This arithmetic-based rule is unique among security and compliance standards, which typically focus on technical controls rather than ownership structures. As of mid-2026, only about a dozen providers have achieved this qualification, including OVHcloud, Scaleway, and 3DS Outscale, with several more in progress.

Because the rule is based on ownership stakes and voting rights, it is a brutally difficult criterion to meet. Scalingo’s CEO described it as a level 10 challenge compared to ISO 27001’s level 1. Major US-based hyperscalers, such as Amazon, remain ineligible for SecNumCloud certification due to their US jurisdiction. Instead, they are creating joint ventures or restructuring control—like Thales-Google’s S3NS or Capgemini-Orange’s Bleu—to meet the ownership limits while maintaining operational control.

This approach allows foreign companies to circumvent direct ownership restrictions but raises questions about the actual sovereignty and legal control of these services, which are still subject to US law and jurisdiction.

At a glance
reportWhen: developing as of mid-2026
The developmentThe 24% ownership rule in France’s SecNumCloud framework exposes critical limitations in assessing AI sovereignty, highlighting ongoing challenges in legal control verification.

Implications of the 24% Control Limit on AI and Cloud Sovereignty

The 24% ownership rule exposes a fundamental challenge in verifying sovereignty through arithmetic limits on ownership. While it offers a clear, checkable metric, it does not fully address control or influence—raising concerns about whether these arrangements truly guarantee legal independence. This development could influence regulatory standards across Europe, as governments seek more effective ways to ensure sovereignty over critical AI and cloud infrastructure, especially amid increasing geopolitical tensions.

Furthermore, the rule’s complexity and the workaround strategies employed by US tech giants highlight ongoing tensions between technical compliance and legal sovereignty. The effectiveness of such ownership caps in guaranteeing actual control remains under scrutiny, potentially prompting revisions or new frameworks in the near future.

Amazon

ISO 27001 cybersecurity certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Sovereignty Testing and the 24% Rule

France’s SecNumCloud framework, created by ANSSI in 2016, aims to ensure legal sovereignty by imposing strict requirements, including EU data residency and immunity from non-EU extraterritorial laws. The ownership cap of 24% was introduced as a simple, arithmetic test to verify control over cloud providers, preventing foreign influence. This approach contrasts with traditional security certifications like ISO 27001 or BSI C5, which focus on security practices rather than ownership.

While most standards test security controls, SecNumCloud’s ownership rule directly targets legal sovereignty. As of 2026, only a limited number of providers have achieved certification, with US-based hyperscalers unable to qualify directly, prompting them to form joint ventures or restructure ownership to meet the threshold.

This framework is part of broader European efforts to maintain control over critical infrastructure and protect against foreign legal influence, especially in sensitive sectors like health, energy, and finance.

“Achieving ISO 27001 is a level 1 challenge; SecNumCloud’s 24% rule is a level 10. It’s brutally hard but necessary for sovereignty.”

— Scalingo CEO

Amazon

cloud security compliance standards

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About Practical Sovereignty Verification

It remains unclear how effective the 24% ownership rule will be in guaranteeing actual control over cloud services, especially given the workarounds employed by US-based providers. The long-term legal and operational implications of these arrangements are still being evaluated, and whether the rule can prevent foreign influence in practice is uncertain. Additionally, questions persist about how regulators will monitor and enforce compliance with these ownership limits.

Amazon

EU data residency cloud services

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Sovereignty Testing and Regulatory Developments

As of mid-2026, more providers are expected to pursue SecNumCloud certification, with ongoing efforts to refine the ownership control framework. European regulators may consider additional measures to address control and influence, possibly moving beyond simple ownership thresholds. The continued use of joint ventures and restructuring strategies by foreign providers suggests that the sovereignty testing landscape will evolve, potentially prompting new standards or revisions to existing frameworks.

Monitoring how regulators and industry respond will be critical, especially regarding the effectiveness of the 24% rule in ensuring true sovereignty.

Amazon

AI sovereignty testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the 24% ownership rule in France’s SecNumCloud framework?

The 24% ownership rule limits individual foreign ownership in cloud providers to 24%, aiming to ensure legal sovereignty by controlling ownership and influence.

Why is the 24% rule considered a breakthrough or limitation?

It provides a clear, arithmetic measure for sovereignty, but it does not fully address control or influence—foreign providers can still exert significant influence through restructuring or joint ventures.

How are US cloud providers responding to the ownership restrictions?

They are creating joint ventures or restructuring control to meet the ownership thresholds, but their services remain subject to US law, raising questions about true sovereignty.

What are the implications for AI sovereignty testing?

The limitations of the 24% rule highlight the need for more comprehensive sovereignty verification methods, especially as AI systems become more integrated into critical infrastructure.

What might happen next in sovereignty regulation?

European regulators may develop additional controls or refine existing standards to better address control and influence, potentially moving beyond simple ownership caps.

Source: ThorstenMeyerAI.com

You May Also Like

Mistral Forge: Owning the Model, Not Just Renting the API

Mistral announces Forge, a platform enabling organizations to build and own their AI models, moving beyond API-based access to full model ownership.

Readiness: Before You Fund the Answer

A new diagnostic tool assesses organizational AI readiness in 20 minutes, helping companies avoid costly failures with world-model AI systems.

The Roblox Cheat That Broke Vercel.

A Roblox auto-farm script downloaded by a Vercel employee via a compromised third-party tool led to a major breach exposing customer data across cloud platforms.

The rails. Why European agentic commerce is co-defined by two converging regimes.

European agentic commerce is being shaped by two converging regulations: PSD3/PSR rebuilding payment rails and the AI Act’s high-risk AI standards, creating a complex legal infrastructure.