AI And Sovereignty: Why The 24% Rule Suggests Certification Gaps
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The French SecNumCloud framework uses a 24% ownership cap to enforce legal sovereignty over cloud providers. This rule exposes certification gaps, especially for foreign-owned providers, raising questions about data control and jurisdiction. The development highlights the limits of existing security certifications in ensuring legal sovereignty.

French cybersecurity authorities have introduced a 24% ownership control rule as part of the SecNumCloud qualification, a government-backed standard that enforces legal sovereignty for cloud providers handling sensitive public-sector data. This development underscores a critical gap in existing certifications, which focus on security practices but do not address jurisdictional control.

The SecNumCloud framework, managed by ANSSI, requires providers to meet over 360 criteria, including EU data residency, audited key custody, and immunity from non-EU extraterritorial laws. Its unique feature is the ownership cap—no individual or group outside the EU can hold more than 24% of voting rights—aimed at ensuring European legal sovereignty.

Currently, about nine to ten providers hold an active SecNumCloud qualification, including OVHcloud and Scaleway, with others in the pipeline. The regulation makes it mandatory for hosting certain sensitive French public data and is likely to expand to critical sectors like health, energy, and finance under broader EU directives.

In contrast, certifications like ISO 27001 or BSI C5 certify security practices but do not address legal control or jurisdiction, leaving gaps for foreign-owned providers operating within the EU market.

At a glance
reportWhen: announced mid-2026, ongoing implementat…
The developmentThe French cybersecurity agency ANSSI has implemented a 24% ownership threshold in the SecNumCloud qualification to ensure legal sovereignty over cloud services, revealing gaps in current certification schemes.

Implications of the 24% Ownership Rule for Data Sovereignty

The 24% ownership threshold introduces a clear, arithmetic measure of ownership control that directly impacts legal jurisdiction over cloud services. It aims to prevent foreign governments from exerting influence through ownership stakes, thus strengthening European data sovereignty.

This approach reveals a fundamental limitation: current security certifications do not account for ownership control. As a result, providers with foreign parent companies can still technically meet security standards but remain subject to extraterritorial laws like the CLOUD Act. The rule effectively creates a new layer of sovereignty, but its success depends on widespread adoption and compliance.

For European regulators and public-sector entities, this could mean a shift toward prioritizing ownership and control metrics over traditional security certifications, influencing procurement decisions and cloud architecture strategies.

Amazon

EU data sovereignty cloud certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Role of Certifications and Legal Control in Cloud Security

Existing certifications such as ISO 27001 and BSI C5 focus on security practices—access controls, encryption, incident response—but do not address jurisdictional control. Meanwhile, frameworks like SecNumCloud, introduced by France’s ANSSI, incorporate legal sovereignty through specific requirements, notably the ownership cap.

Historically, cloud providers like AWS have obtained multiple security attestations but remain subject to US laws, including the CLOUD Act. The introduction of the 24% rule aims to bridge the gap between security practice and legal control, but it is a novel measure that challenges traditional certification paradigms.

US hyperscalers have responded by restructuring ownership—such as Thales and Capgemini controlling operations—to meet the ownership threshold, thus maintaining access to the EU market while avoiding sovereignty conflicts.

“SecNumCloud is designed to ensure that providers operating within France meet strict legal and security standards, including ownership control.”

— ANSSI spokesperson

Amazon

cloud security compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions About Certification Efficacy and Enforcement

It remains unclear how broadly the ownership cap will be enforced across the EU, especially outside France. The long-term impact on foreign providers and whether this will lead to significant market shifts are still developing questions.

Additionally, the effectiveness of the rule in preventing foreign government influence depends on compliance and transparency, which are challenging to verify uniformly. There is also uncertainty about how other EU countries will adopt or adapt similar sovereignty measures.

Amazon

ownership control cloud security solutions

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Adoption and Regulatory Evolution

Expect continued implementation of the ownership threshold in France, with increasing pressure on foreign providers to restructure ownership or withdraw from certain sectors. The EU may consider harmonizing sovereignty standards, potentially adopting similar caps or controls.

Regulatory authorities are likely to monitor compliance closely, and legal challenges or clarifications could shape future policy. Meanwhile, providers will need to evaluate their ownership structures and control mechanisms to remain compliant.

Amazon

EU compliant cloud service providers

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the significance of the 24% ownership rule?

The 24% ownership rule is a legal sovereignty measure that limits foreign control over cloud providers, aiming to prevent foreign governments from exerting influence through ownership stakes, thus strengthening European jurisdiction over data.

No. Certifications like ISO 27001 or BSI C5 verify security practices but do not address ownership or jurisdiction. The SecNumCloud framework introduces ownership controls as a supplement to security standards.

How are foreign providers responding to the ownership cap?

Some providers are restructuring ownership, such as Thales and Capgemini controlling operations, to meet the 24% threshold, thus maintaining market access while complying with sovereignty requirements.

Will the 24% rule be adopted outside France?

It is uncertain. While France is leading with this measure, other EU countries may consider similar controls, but widespread adoption depends on regulatory consensus and market dynamics.

Source: ThorstenMeyerAI.com

You May Also Like

Top 5 Reasons Why AI Security Is a Game Changer in Cybersecurity

AIThis post was created with the assistance of artificial intelligence (AI). As…

AI Security: The New Frontier in Cyber Defense

AIThis post was created with the assistance of artificial intelligence (AI). As…

Why Smart Locks Are Part of Office Security Conversations Now

Smart locks are transforming office security by offering remote control and instant access management—discover why they’re now essential.

Protecting AI Models From Prompt‑Injection Attacks

Implementing robust security measures is essential to safeguard AI models from prompt-injection attacks, but the key to effective protection lies in understanding…