The Impact Of The 24% Rule On Perceptions Of AI Sovereignty Certification Integrity
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The 24% ownership rule in France’s SecNumCloud framework is reshaping how AI providers are viewed regarding sovereignty. It emphasizes ownership control over traditional security certifications, impacting provider strategies and perceptions.

The 24% ownership rule in France’s SecNumCloud framework is transforming how AI and cloud providers are evaluated for sovereignty, emphasizing ownership control over traditional security certifications. This rule is causing providers to alter control structures to meet sovereignty criteria, impacting the perception of compliance and sovereignty in European cloud services.

SecNumCloud, created by France’s ANSSI, introduces a unique sovereignty test based on a simple arithmetic cap: 24% of voting rights held by non-EU companies. This ownership threshold is designed to ensure that control remains within European jurisdiction, providing a clear legal sovereignty indicator. As of mid-2026, roughly ten providers, including OVHcloud and Scaleway, have obtained active qualifications, with others in the pipeline.

Unlike traditional certifications like ISO 27001 or BSI C5, which focus on security practices, SecNumCloud’s ownership rule directly addresses legal sovereignty. It mandates EU domicile, EU-only data storage, and immunity from non-EU extraterritorial law, with the 24% ownership cap being the critical measure of control. This makes it a practical, arithmetic-based test, distinct from policy or control-based certifications.

Major US-based cloud providers, such as AWS, cannot qualify directly under SecNumCloud due to their ownership structures. Instead, they are creating control arrangements—such as joint ventures or control by European entities—to meet the ownership threshold, exemplified by partnerships like Thales–Google S3NS and Capgemini–Orange Bleu. These arrangements are designed explicitly to comply with the sovereignty rule while maintaining operational control.

At a glance
reportWhen: developing, as of mid-2026
The developmentThe 24% ownership cap in France’s SecNumCloud framework is significantly affecting perceptions of AI sovereignty certification, with providers adjusting control structures to meet sovereignty requirements.

Why the 24% Ownership Cap Reshapes Sovereignty Perceptions

The 24% ownership rule fundamentally shifts how sovereignty is understood in European cloud and AI services. It moves the focus from security practices alone to ownership and control, which are now seen as essential for legal sovereignty. This impacts not only provider strategies but also procurement decisions, as organizations seek to ensure their data remains under European control and immune from non-EU laws.

For vendors, the rule acts as a clear, measurable threshold, providing transparency and enforceability. For regulators and clients, it offers a concrete indicator of sovereignty, influencing procurement and compliance strategies. The rule’s strict arithmetic nature makes sovereignty a checkable, verifiable condition, potentially setting a global standard for sovereignty assessments.

Amazon

EU data sovereignty cloud certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Sovereignty Certification and Control Measures

France’s SecNumCloud was introduced in 2016 to establish a government-backed qualification for cloud providers handling sensitive data. Unlike traditional security certifications, it emphasizes legal sovereignty through controls like EU data residency, legal jurisdiction, and immunity from extraterritorial laws. The key feature is the ownership cap: 24% of voting rights held by non-EU entities.

This rule emerged amid increasing concerns about data sovereignty and extraterritorial legal risks, especially from US-based providers subject to laws like the CLOUD Act. It aims to ensure that control remains within the EU, providing a practical measure of sovereignty that complements existing security standards.

Major providers have responded by restructuring ownership or control arrangements to meet the 24% threshold, often through joint ventures or controlling entities based in Europe. This approach reflects a shift from purely technical compliance to legal and ownership control as the core sovereignty criterion.

“The 24% ownership rule is a practical, arithmetic-based test that makes sovereignty verifiable and enforceable, moving beyond traditional security certifications.”

— Thorsten Meyer

Amazon

European cloud provider control solutions

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Uncertainties Surrounding Implementation and Global Impact

It remains unclear how widely the ownership rule will influence non-French or broader European cloud markets, especially outside France. The effectiveness of control arrangements to meet the 24% cap without compromising operational flexibility is still being tested. Additionally, the long-term impact on US-based providers and their strategies for European markets is uncertain, as legal and regulatory responses evolve.

Further, the extent to which other European countries might adopt similar sovereignty measures based on ownership thresholds remains unknown, as does the potential for legal challenges or reinterpretations of the rule.

Amazon

AI sovereignty compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps in Sovereignty Certification and Market Adaptation

Providers are expected to continue restructuring ownership and control models to meet the 24% threshold, with several more candidates pursuing SecNumCloud qualifications. Regulatory bodies may refine or expand the rule’s application, particularly for critical infrastructure and public sector data.

Monitoring how European regulators and clients respond to these ownership-based sovereignty measures will be key. Additionally, legal developments or disputes concerning control and jurisdiction could influence the future shape of sovereignty certification frameworks.

Amazon

European data residency cloud services

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is the 24% ownership rule in SecNumCloud?

The 24% ownership rule restricts non-EU voting rights to 24% of a provider’s voting shares, ensuring control remains within European jurisdiction and providing a clear measure of legal sovereignty.

How does the 24% rule differ from traditional security certifications?

Traditional certifications like ISO 27001 focus on security practices, while the 24% ownership rule directly addresses legal control and sovereignty, making it a control-based, arithmetic threshold.

Can US-based cloud providers qualify under SecNumCloud?

Not directly, due to ownership restrictions. They are creating control arrangements—such as joint ventures or control by European entities—to meet the 24% ownership threshold.

What are the implications for providers trying to meet sovereignty requirements?

Providers must restructure ownership or control models to ensure non-EU ownership remains below 24%, often involving complex legal and operational arrangements.

Will other European countries adopt similar sovereignty rules?

This remains uncertain; while France’s model influences policy, broader adoption depends on regulatory developments and regional legal considerations.

Source: ThorstenMeyerAI.com

You May Also Like

Trade and supply-chain operations signal monitor: Federal judge blocks Trump effort to make voters show proof of citizenship

A federal judge has blocked former President Trump’s attempt to mandate proof of citizenship for voters, impacting election and trade-related legal strategies.

AI Integration: Slow To Start, Hard To Displace

Analysis of why enterprise AI adoption remains slow and how incumbents remain resilient despite disruption efforts.

Trade and supply-chain operations signal monitor: MEPs urge FIFA to investigate chief Infantino over Trump peace prize

European MEPs call for FIFA to investigate Infantino amid trade and geopolitical signals highlighting potential issues in operations management.

Engineering Is Automated. Research Is the Residual.

Recent developments show AI can automate most engineering tasks in AI R&D, but research remains partly human-driven. The implications are significant for the future of AI innovation.