📊 Full opportunity report: How The 24% Rule Reveals The False Promises Of AI Sovereign Cloud Certifications on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

The 24% ownership rule in France’s SecNumCloud framework exposes the limitations of current European sovereignty certifications. Despite claims of sovereignty, US-based providers can still control data through structural ownership arrangements, challenging the promise of true data sovereignty.

European cloud sovereignty frameworks such as France’s SecNumCloud include a key ownership cap of 24% for foreign entities, which aims to limit non-EU control over cloud providers. However, this rule does not prevent US-based companies from exerting control through structural arrangements, exposing a gap between certification claims and actual sovereignty.

SecNumCloud, managed by France’s ANSSI, is a government-backed qualification designed to ensure legal sovereignty over cloud services hosting sensitive data within the EU. Its defining feature is the ownership control rule: foreign companies cannot hold more than 24% ownership individually, or 39% collectively, to maintain sovereignty. This arithmetic-based control measure is unique among European certifications and is intended to prevent non-EU legal reach.

Despite this, US technology giants like Amazon, Microsoft, and Google have found ways to maintain control by restructuring ownership. For example, joint ventures such as Thales-Google’s S3NS and Capgemini-Orange’s Bleu, where US firms hold operational or strategic control, are certified under the framework. These arrangements allow US companies to retain significant influence while complying with the ownership cap, raising questions about the effectiveness of the sovereignty claim.

Experts like Scalingo’s CEO emphasize that achieving compliance with SecNumCloud’s ownership rules is extremely complex—comparable to a level 10 on a 1-10 scale of difficulty—making genuine sovereignty difficult for many providers. As of mid-2026, roughly ten providers, including OVHcloud and Scaleway, hold active certifications, but the structure of control remains a concern.

At a glance
analysisWhen: developing; as of mid-2026
The developmentThe article examines how the 24% ownership cap in France’s SecNumCloud framework reveals the limitations of European cloud sovereignty certifications, especially for US tech giants.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications of the 24% Control Limit for Data Sovereignty

The 24% ownership rule in SecNumCloud highlights a fundamental challenge in achieving true European data sovereignty. While certifications like SecNumCloud and C5 attest to technical and organizational controls, they do not fully address the legal reach of foreign governments. US-based firms can still exert control through ownership structures, undermining the sovereignty claims that these certifications promote. This gap matters because it affects how governments, businesses, and regulators interpret security and sovereignty assurances in cloud services.

For European regulators and clients, the key takeaway is that certifications alone do not guarantee immunity from extraterritorial laws like the CLOUD Act. The ownership cap is a step toward sovereignty but does not eliminate control risks entirely. This discrepancy could influence procurement decisions and the future development of European cloud policies, especially as US tech giants adapt their structures to meet these rules.

Amazon

European cloud sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Cloud Certifications and Sovereignty Challenges

European cloud security standards such as ISO 27001, SOC 2, and BSI C5 focus on security practices—covering access controls, encryption, incident response, and auditability—without addressing legal jurisdiction or control. In contrast, France’s SecNumCloud introduces a legal sovereignty criterion through the ownership control rule, reflecting a broader push for sovereignty within the EU.

However, US hyperscalers like AWS, Microsoft, and Google are structurally ineligible for direct SecNumCloud certification due to their US-based ownership and control. These companies have responded by creating joint ventures or restructuring ownership to stay within the 24% limit while maintaining operational control, effectively bypassing the sovereignty intent of the regulation.

This situation exposes a tension between technical compliance and legal sovereignty, raising questions about whether current frameworks can truly prevent foreign legal influence over EU data infrastructure.

“If the complexity of achieving ISO 27001 is a 1, SecNumCloud is a 10.”

— Scalingo CEO

Co-governed Sovereignty Network: Legal Basis and Its Prototype & Applications with MIN Architecture

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Actual Sovereignty Achieved Under the 24% Rule

It remains unclear how effectively the 24% ownership cap prevents foreign influence in practice, especially given the creative structuring of ownership by US firms. While the rule limits direct control, the impact of indirect influence through operational control or strategic partnerships is still under assessment. Moreover, legal and political challenges to these arrangements are evolving, and the full implications are yet to be seen.

SOC2 Cloud Compliance Mastery: Master SOC 2 For Cloud Tools | Secure Collaboration Fast | SOC 2 Controls Simplified | Trusted Compliance Blueprint | Fast-Track Cloud Compliance | SOC 2 For SaaS

SOC2 Cloud Compliance Mastery: Master SOC 2 For Cloud Tools | Secure Collaboration Fast | SOC 2 Controls Simplified | Trusted Compliance Blueprint | Fast-Track Cloud Compliance | SOC 2 For SaaS

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Future Developments in European Cloud Sovereignty Policies

Regulators and policymakers are likely to scrutinize ownership structures more closely and may introduce additional measures to reinforce sovereignty, such as stricter controls on operational influence or new legal barriers. US firms are expected to adapt further, possibly by increasing local ownership or establishing European subsidiaries to meet sovereignty standards more transparently. The ongoing debate over the effectiveness of current certifications will influence future regulatory frameworks and procurement practices.

Shelly Smart Plug UL, WiFi, Bluetooth, Zigbee, Matter Outlet with Power Metering, Works with HomeKit, Google Home, Alexa, Home Assistant, Smart Socket, Easy Setup, Remote Control, Plug US Gen4 Black

Shelly Smart Plug UL, WiFi, Bluetooth, Zigbee, Matter Outlet with Power Metering, Works with HomeKit, Google Home, Alexa, Home Assistant, Smart Socket, Easy Setup, Remote Control, Plug US Gen4 Black

Shelly Plus US Gen4 – A Matter-certified smart plug featuring precise power monitoring, Wi-Fi, Bluetooth, Zigbee connectivity, 1800W…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Does SecNumCloud certification guarantee data sovereignty?

No, certification primarily attests to security practices and legal compliance within the EU, but US firms can still exert control through ownership and operational arrangements.

Can US-based cloud providers fully comply with European sovereignty rules?

Not entirely, due to legal restrictions like the CLOUD Act. They often use joint ventures or restructuring to meet ownership limits but may still retain influence.

What is the significance of the 24% ownership cap?

It is designed to limit foreign control over cloud providers, but its effectiveness depends on how ownership and control are structured and enforced.

Are there alternatives to current European sovereignty certifications?

Yes, some proposals include stricter legal restrictions, local ownership requirements, or new frameworks that address operational influence more directly.

How does this affect European public sector data hosting?

Under France’s Cloud au Centre doctrine, SecNumCloud is mandatory for hosting sensitive public data, but the ownership control limits still leave some sovereignty gaps open.

Source: ThorstenMeyerAI.com

You May Also Like

Threat Modeling for Startups That Don’t Have a Security Team

Protect your startup by understanding threat modeling essentials, even without a dedicated security team—discover how to stay ahead of cyber risks today.

How to Ventilate a Small Printing Space Safely

Just by understanding your space and implementing key ventilation strategies, you can ensure safety—discover how to ventilate your small printing area effectively.

The Regulatory Vacuum.

Google disclosed a zero-day vulnerability exploited by threat actors on May 11, 2026, revealing a lack of existing regulatory frameworks for AI-driven cyber threats.

Why Global Progress Depends On Prioritizing The Best AI Model Over Sovereign Concerns

Analysis of why adopting the best AI models, rather than sovereign clouds, is crucial for technological advancement and competitiveness.