Understanding The Limits Of AI Sovereignty Testing Via The 24% Rule
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

FOR BUSINESS

Open a free Amazon Business account

Business pricing, bulk buying and tax-exempt orders.

Create a free account

As an affiliate, we earn on qualifying purchases.

France’s SecNumCloud framework introduces a unique sovereignty test based on a 24% ownership limit. This rule aims to ensure legal control over data by restricting foreign ownership, but its practical application and impact on providers remain complex and evolving.

France’s national cybersecurity agency, ANSSI, has implemented a new sovereignty test within its SecNumCloud qualification scheme, requiring providers to ensure that foreign ownership does not exceed 24%. This rule is designed to safeguard legal control over data and is a key part of France’s efforts to enforce data sovereignty in cloud and AI services.

The SecNumCloud qualification, created in 2016 and now at version 3.2, is not a traditional certification but a government-issued qualification that guarantees a service’s compliance with strict legal sovereignty criteria. Among its requirements are EU data storage, audited key custody, and immunity from non-EU extraterritorial laws.

The 24% ownership rule is the core of this sovereignty test, limiting the individual foreign ownership stake to 24% and collective foreign ownership to 39%. This arithmetic cap is intended to prevent foreign governments from exerting control over cloud providers, thereby ensuring legal sovereignty. Achieving compliance with this rule is considered highly challenging, with only about ten providers holding an active SecNumCloud qualification as of mid-2026.

Major providers such as OVHcloud, 3DS Outscale, and Scaleway have obtained the qualification, which is mandatory for hosting sensitive French public-sector data and increasingly for other critical sectors. US-based hyperscalers face structural barriers to certification because of their ownership structures, prompting some to modify control arrangements to meet the 24% cap, such as through joint ventures or operational control models.

At a glance
analysisWhen: developing as of mid-2026
The developmentThe article examines France’s SecNumCloud sovereignty rule, specifically the 24% ownership cap, and explores its implications for AI and cloud service providers operating in Europe.

Implications of the 24% Ownership Cap for Cloud Providers

The 24% ownership rule represents a significant shift in how European nations enforce data sovereignty, directly impacting international cloud and AI vendors. It emphasizes ownership control over traditional security certifications, aiming to prevent foreign government influence over data stored within EU jurisdictions.

This development matters because it introduces a new, arithmetic-based sovereignty benchmark that is checkable from a cap table, making sovereignty more transparent and enforceable. For providers, especially US-based hyperscalers, it means restructuring ownership or control models to comply, potentially affecting their global operations and legal exposure. For European customers, it promises greater control over data sovereignty but also raises questions about market access and competitive fairness.

Amazon

cloud sovereignty compliance software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Sovereignty Frameworks and the 24% Control Limit

France’s SecNumCloud scheme, created by ANSSI, is unique in its explicit legal sovereignty requirements, including the 24% ownership cap. It builds upon ISO 27001 but adds legal and ownership controls, making it a more prescriptive and government-backed qualification.

In contrast, Germany’s BSI C5 standard, established in 2016, focuses on security controls and control disclosures but does not impose ownership restrictions. While C5 requires providers to disclose jurisdiction and data location, it does not prevent foreign control, leaving residual sovereignty risks.

Major US cloud providers like AWS and Microsoft face structural barriers to certification under these frameworks because of their ownership structures. To comply, some have formed joint ventures or operational control arrangements, such as Thales–Google’s S3NS and Capgemini–Orange’s Bleu, which meet the ownership caps while maintaining US parentage.

Amazon

data sovereignty certification tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About the 24% Control Limit’s Impact

It remains unclear how broadly the 24% ownership rule will be adopted across Europe, especially outside France, and how it will influence market dynamics in the long term. The practical challenges providers face in restructuring ownership or control models are still being tested, and the full legal implications of the rule are yet to be seen in courts or policy debates.

Additionally, it is uncertain how the rule will interact with existing international laws and treaties, and whether it will be challenged or adapted as more providers attempt to meet its requirements.

Amazon

ownership structure analysis software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Compliance and Market Adoption

As of mid-2026, more providers are expected to seek SecNumCloud qualification, especially those handling sensitive data for French public sector and critical infrastructure. The development of joint ventures and control arrangements to meet the 24% cap will continue, potentially setting a precedent for other European countries to adopt similar sovereignty measures.

Regulators and policymakers may refine or expand the framework, and legal challenges or clarifications could influence its future scope. Monitoring how providers adapt their ownership structures will be crucial for understanding the evolving landscape of European data sovereignty.

Amazon

cybersecurity compliance audit tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the 24% ownership rule in France’s SecNumCloud?

The 24% ownership rule limits individual foreign ownership in cloud providers to 24%, and collective foreign ownership to 39%, as a way to ensure legal sovereignty over stored data.

Why is this rule significant for US cloud providers?

US providers typically have ownership structures that exceed these limits, making it difficult or impossible for them to qualify directly under SecNumCloud. They may need to restructure control or form joint ventures to comply.

Does a certification guarantee immunity from foreign laws?

No. Certifications like SecNumCloud or C5 demonstrate security practices or control disclosures but do not automatically shield providers from laws like the CLOUD Act or extraterritorial jurisdiction.

How does this impact data sovereignty in Europe?

It enhances legal control over data stored within EU jurisdictions, reducing foreign influence and increasing transparency about ownership, but also complicates market access for foreign providers.

Will the 24% rule be adopted outside France?

It is uncertain. While other European countries may consider similar measures, the specific implementation and legal framework will vary, and broader adoption remains to be seen.

Source: ThorstenMeyerAI.com

COLLEGE MOVE-IN

College move-in / dorm season Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Capability or Control: The European Enterprise AI Playbook for the AI Act Era

A comprehensive guide for European companies navigating AI capability and control under the EU AI Act, focusing on compliance, licensing, and sovereignty.

Loan covenant calendar for bootstrapped companies

A new workflow tool for small, bootstrapped firms to manage loan covenants is being tested, aiming to improve compliance and lender communication.

The AI Act’s Deadline Crunch: What August 2 Revealed About AI Policy

The EU AI Act’s enforcement schedule shifted, but key transparency obligations remain in effect from August 2, 2026, affecting many organizations.

AI compliance brief generator for small clinics

A new AI tool for small clinics to generate weekly compliance briefs is entering testing, aiming to streamline regulatory updates for healthcare providers.