How The 24% Rule Challenges The Credibility Of AI Sovereignty Certifications
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

The 24% ownership cap in France’s SecNumCloud framework tests legal sovereignty, challenging the credibility of traditional security certifications. This impacts how providers demonstrate control over data and jurisdiction.

France’s SecNumCloud framework introduces a 24% ownership cap that tests legal sovereignty over cloud services, challenging the credibility of traditional security certifications in demonstrating control over data jurisdiction. This development has significant implications for providers and regulators, especially in the context of AI and sensitive data hosting.

The 24% ownership rule is a key criterion of France’s SecNumCloud qualification, established by ANSSI, France’s national cybersecurity agency. It stipulates that foreign companies must hold no more than 24% of voting rights or capital in a provider to qualify, effectively ensuring EU legal sovereignty.

Unlike typical security certifications such as ISO 27001 or SOC 2, which certify security practices, SecNumCloud’s ownership rule directly tests who controls the provider and under which jurisdiction it operates. This makes it a legal sovereignty test, not merely a security standard.

As of mid-2026, approximately nine to ten providers hold an active SecNumCloud qualification, including OVHcloud, Outscale, and Scaleway, with more in the pipeline. The rule is mandatory for hosting sensitive French public-sector data and is expected to extend to critical infrastructure sectors.

At a glance
reportWhen: developing as of mid-2026
The developmentThe 24% ownership rule in France’s SecNumCloud framework is reshaping perceptions of AI sovereignty certifications and legal control over data.

Implications of the 24% Ownership Cap on Data Control

The 24% ownership rule fundamentally shifts how sovereignty is demonstrated in cloud services. It emphasizes ownership and control over legal jurisdiction, challenging the reliance on traditional security certifications that do not address legal sovereignty.

This development could influence global cloud procurement and regulatory standards, especially as other European countries consider similar legal sovereignty measures. It also complicates the landscape for US-based hyperscalers operating in Europe, as they must adapt control structures to meet sovereignty criteria without losing access to local markets.

Ultimately, this rule raises questions about the credibility and sufficiency of current AI and cloud certifications in ensuring legal control over data, which is critical for sensitive applications like AI training and deployment.

Amazon

ISO 27001 security certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background of Sovereignty and Certification Standards

Traditional security certifications such as ISO 27001, SOC 2, and BSI C5 focus on security practices — access controls, encryption, incident response — without addressing legal jurisdiction. These certifications are widely recognized but do not prevent a provider from being subject to extraterritorial laws like the US CLOUD Act.

France’s SecNumCloud was introduced in 2016 to go beyond security practices by embedding legal sovereignty requirements, including EU data storage, audited key custody, and a ownership cap of 24%. This approach directly tests who owns and controls the provider, not just how it operates.

Meanwhile, in Germany, the BSI C5 scheme certifies control implementation but does not explicitly address jurisdiction or ownership. Both frameworks highlight the growing importance of legal control in cloud security standards.

“SecNumCloud is designed to ensure that providers are not only secure but also under EU jurisdiction, with ownership limits as a core component.”

— Anssi representative

Amazon

cloud security compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Impact on Global Cloud and AI Strategies

It is still unclear how widely the ownership rule will influence international cloud providers and AI deployment. US hyperscalers are adapting control structures, but the exact legal and operational implications are still evolving. Additionally, the long-term effectiveness of the ownership cap in ensuring EU data sovereignty remains to be seen, especially as providers seek ways to circumvent or comply with the rule.

Further, the potential for legal challenges or policy shifts could alter the framework’s impact, making the future landscape uncertain.

Amazon

data sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps in Sovereignty Certification and Market Adoption

Expect more providers to pursue SecNumCloud certification as the framework becomes mandatory for sensitive data hosting in France and potentially other EU countries. Providers will likely explore control structures to meet the 24% ownership limit, including joint ventures or ownership restructuring.

Regulators and industry bodies may also develop new standards or adaptations based on the sovereignty model, influencing global certification practices. Monitoring how US and other non-EU providers respond will be critical in understanding the future of AI sovereignty and cloud control.

Amazon

cybersecurity audit software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does the 24% ownership rule differ from traditional security certifications?

The 24% rule specifically tests who owns and controls the provider, focusing on legal sovereignty, whereas traditional certifications like ISO 27001 mainly assess security practices.

Can a provider with a high percentage of US ownership meet the sovereignty requirements?

Yes, but they must structure ownership so that no individual or combined foreign entity exceeds 24%, often through joint ventures or control arrangements, which complicates compliance.

Will the ownership rule prevent US hyperscalers from operating in Europe?

Not necessarily. US hyperscalers can still operate by restructuring control and ownership, but they must adhere to the 24% cap and demonstrate legal sovereignty compliance.

Does SecNumCloud certification guarantee immunity from US or other extraterritorial laws?

No. While it tests control and jurisdiction, it does not exempt providers from laws like the CLOUD Act. It aims to limit control by foreign laws but cannot eliminate legal exposure entirely.

How might this influence AI deployment and sovereignty?

The framework emphasizes ownership and control over data, which could lead to more localized AI training and deployment within EU-controlled providers, affecting global AI strategies.

Source: ThorstenMeyerAI.com

You May Also Like

The NVIDIA Earnings Preview: What Q1 FY27 Will Reveal About the AI Cycle

Preview of NVIDIA’s upcoming Q1 FY27 earnings report, highlighting expected revenue, market implications, and the significance for the AI cycle.

Amazon is facing a class action lawsuit for not refunding its customers after ‘unlawful’ tariffs

Amazon is sued for allegedly not refunding customers for tariffs imposed during the Trump administration, despite legal rulings allowing such refunds.

Building an AI Trading Bot — Week One: Why a 90 % Win Rate Can Still Lose Money

Initial experiments with AI trading strategies reveal high win rates do not guarantee profits. Key insights from a simulated trading lab experiment.

Rates Spark: The Damage Has Been Done

Recent rate hikes have caused significant market damage, with effects already evident. The full impact is now unfolding, raising concerns among investors.