📊 Full opportunity report: The Limitations Of AI Sovereignty Testing Revealed By The 24% Rule on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership threshold in France’s SecNumCloud framework reveals fundamental challenges in verifying AI sovereignty. This development questions the effectiveness of current sovereignty tests and their practical implications for cloud providers.

France’s national cybersecurity agency, ANSSI, has implemented a 24% ownership cap as part of its SecNumCloud framework, a key sovereignty requirement for cloud providers hosting sensitive data within the EU. This rule directly tests the ownership and control of foreign companies over cloud services, marking a significant development in sovereignty verification. The rule’s practical impact is already influencing provider strategies and regulatory compliance, making it a critical point of focus for European and international cloud providers.

The 24% ownership threshold in the SecNumCloud framework is designed to ensure legal sovereignty by limiting foreign ownership of companies controlling cloud infrastructure. This arithmetic-based rule is unique among security and compliance standards, which typically focus on technical controls rather than ownership structures. As of mid-2026, only about a dozen providers have achieved this qualification, including OVHcloud, Scaleway, and 3DS Outscale, with several more in progress.

Because the rule is based on ownership stakes and voting rights, it is a brutally difficult criterion to meet. Scalingo’s CEO described it as a level 10 challenge compared to ISO 27001’s level 1. Major US-based hyperscalers, such as Amazon, remain ineligible for SecNumCloud certification due to their US jurisdiction. Instead, they are creating joint ventures or restructuring control—like Thales-Google’s S3NS or Capgemini-Orange’s Bleu—to meet the ownership limits while maintaining operational control.

This approach allows foreign companies to circumvent direct ownership restrictions but raises questions about the actual sovereignty and legal control of these services, which are still subject to US law and jurisdiction.

At a glance
reportWhen: developing as of mid-2026
The developmentThe 24% ownership rule in France’s SecNumCloud framework exposes critical limitations in assessing AI sovereignty, highlighting ongoing challenges in legal control verification.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Control Limit on AI and Cloud Sovereignty

The 24% ownership rule exposes a fundamental challenge in verifying sovereignty through arithmetic limits on ownership. While it offers a clear, checkable metric, it does not fully address control or influence—raising concerns about whether these arrangements truly guarantee legal independence. This development could influence regulatory standards across Europe, as governments seek more effective ways to ensure sovereignty over critical AI and cloud infrastructure, especially amid increasing geopolitical tensions.

Furthermore, the rule’s complexity and the workaround strategies employed by US tech giants highlight ongoing tensions between technical compliance and legal sovereignty. The effectiveness of such ownership caps in guaranteeing actual control remains under scrutiny, potentially prompting revisions or new frameworks in the near future.

Principles of Agentic AI Governance: A Playbook for Managing AI Risk, Fairness, and Compliance (Agentic Governance and Architecture)

Principles of Agentic AI Governance: A Playbook for Managing AI Risk, Fairness, and Compliance (Agentic Governance and Architecture)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Sovereignty Testing and the 24% Rule

France’s SecNumCloud framework, created by ANSSI in 2016, aims to ensure legal sovereignty by imposing strict requirements, including EU data residency and immunity from non-EU extraterritorial laws. The ownership cap of 24% was introduced as a simple, arithmetic test to verify control over cloud providers, preventing foreign influence. This approach contrasts with traditional security certifications like ISO 27001 or BSI C5, which focus on security practices rather than ownership.

While most standards test security controls, SecNumCloud’s ownership rule directly targets legal sovereignty. As of 2026, only a limited number of providers have achieved certification, with US-based hyperscalers unable to qualify directly, prompting them to form joint ventures or restructure ownership to meet the threshold.

This framework is part of broader European efforts to maintain control over critical infrastructure and protect against foreign legal influence, especially in sensitive sectors like health, energy, and finance.

“Achieving ISO 27001 is a level 1 challenge; SecNumCloud’s 24% rule is a level 10. It’s brutally hard but necessary for sovereignty.”

— Scalingo CEO

Amazon

cloud sovereignty testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About Practical Sovereignty Verification

It remains unclear how effective the 24% ownership rule will be in guaranteeing actual control over cloud services, especially given the workarounds employed by US-based providers. The long-term legal and operational implications of these arrangements are still being evaluated, and whether the rule can prevent foreign influence in practice is uncertain. Additionally, questions persist about how regulators will monitor and enforce compliance with these ownership limits.

The Operational Excellence Library; Mastering Cybersecurity Compliance Software

The Operational Excellence Library; Mastering Cybersecurity Compliance Software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Sovereignty Testing and Regulatory Developments

As of mid-2026, more providers are expected to pursue SecNumCloud certification, with ongoing efforts to refine the ownership control framework. European regulators may consider additional measures to address control and influence, possibly moving beyond simple ownership thresholds. The continued use of joint ventures and restructuring strategies by foreign providers suggests that the sovereignty testing landscape will evolve, potentially prompting new standards or revisions to existing frameworks.

Monitoring how regulators and industry respond will be critical, especially regarding the effectiveness of the 24% rule in ensuring true sovereignty.

Cognitive Freedom: Learning to Think With AI in the Age of Information Warfare (The Intellectual Enlightenment™ Certification Series)

Cognitive Freedom: Learning to Think With AI in the Age of Information Warfare (The Intellectual Enlightenment™ Certification Series)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the 24% ownership rule in France’s SecNumCloud framework?

The 24% ownership rule limits individual foreign ownership in cloud providers to 24%, aiming to ensure legal sovereignty by controlling ownership and influence.

Why is the 24% rule considered a breakthrough or limitation?

It provides a clear, arithmetic measure for sovereignty, but it does not fully address control or influence—foreign providers can still exert significant influence through restructuring or joint ventures.

How are US cloud providers responding to the ownership restrictions?

They are creating joint ventures or restructuring control to meet the ownership thresholds, but their services remain subject to US law, raising questions about true sovereignty.

What are the implications for AI sovereignty testing?

The limitations of the 24% rule highlight the need for more comprehensive sovereignty verification methods, especially as AI systems become more integrated into critical infrastructure.

What might happen next in sovereignty regulation?

European regulators may develop additional controls or refine existing standards to better address control and influence, potentially moving beyond simple ownership caps.

Source: ThorstenMeyerAI.com

You May Also Like

A Skill Is a Folder, Not a Prompt: What Anthropic Learned Running Hundreds of Them

Anthropic reveals that ‘Skills’ are folders containing instructions, scripts, and assets, transforming AI prompt engineering into durable organizational assets.

Outcome-First Decisions: Keep, Change, or Kill

Thorsten Meyer AI released Outcome-First Decisions, an AGPL-3.0 framework for portfolio reviews that returns keep, change or kill verdicts.

The Agent Trap: Why 90% of AI “Launches” Are Infrastructure Liars

Most AI ‘agent’ launches in 2026 are feature upgrades, not true autonomous platforms. This shift impacts enterprise security and procurement.

The Safety Card, Played From Every Side: David Sacks, Anthropic, and the Fable Standoff

White House claims Anthropic refused to fix a cyberweapon jailbreak, leading to model ban; Anthropic disputes the severity, raising questions about safety claims.