Why Many AI Sovereign Cloud Certifications Are Incomplete, According To The 24% Rule

📊 Full opportunity report: Why Many AI Sovereign Cloud Certifications Are Incomplete, According To The 24% Rule on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

A recent analysis reveals that 24% of AI sovereign cloud providers lack full compliance with ownership sovereignty standards. Certifications alone do not guarantee legal control, raising questions about actual sovereignty. This impacts industries handling sensitive data in Europe.

Approximately 24% of AI sovereign cloud providers examined in a recent report do not fully meet the ownership sovereignty requirements mandated by European standards, despite holding multiple certifications. This raises concerns about whether these providers truly offer legal control over data, which is critical for regulated industries in Europe.

The analysis highlights that while many cloud providers display certifications such as ISO 27001, SOC 2, and BSI C5, these primarily verify security practices rather than legal sovereignty. The key issue is ownership control, specifically the 24% rule—a strict threshold that limits foreign ownership to 24% individually, or 39% collectively, for providers claiming sovereignty under French regulations. This criterion is unique and arithmetic-based, making it a clear measure of legal control.

As of mid-2026, around nine to ten providers have achieved the SecNumCloud qualification, which enforces sovereignty through ownership caps, EU data residency, and immunity from extraterritorial laws. However, many providers with international backing, including US-based giants, still face the challenge of meeting this ownership standard. Notably, some have created joint ventures or structured control to comply, such as Thales with Google or Capgemini with Orange, to circumvent direct foreign ownership limits while maintaining operational control.

Experts emphasize that certifications like C5 or ISO 27001 do not address sovereignty issues directly; they focus on security controls and operational practices. The 24% ownership rule is a distinct, arithmetic measure that directly tests legal control, making it a more definitive indicator of sovereignty compliance.

At a glance
reportWhen: mid-2026
The developmentA report shows that 24% of AI sovereign cloud providers do not meet ownership sovereignty criteria, despite holding various certifications.
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Implications for Data Sovereignty and Regulatory Compliance

This finding underscores that certifications alone do not guarantee sovereignty. For European industries handling sensitive data, especially in sectors like health, finance, and energy, legal control over data is essential. The 24% ownership threshold provides a clear, measurable standard that impacts procurement decisions and regulatory compliance. Companies relying solely on certificates may overestimate their sovereignty status, risking legal exposure or non-compliance with European data laws.

Practical Introduction to ISO 27001: Based On The Latest Version of ISO/IEC 27001:2022 And Its 2024 Amendment

Practical Introduction to ISO 27001: Based On The Latest Version of ISO/IEC 27001:2022 And Its 2024 Amendment

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

European Sovereignty Standards and Certification Limitations

European regulators have emphasized sovereignty, especially through frameworks like SecNumCloud and the 24% ownership rule, introduced by France’s ANSSI. These standards aim to ensure that providers hosting sensitive public-sector and critical infrastructure data are under European legal control, including restrictions on non-EU ownership and extraterritorial laws. However, many providers with international ownership structures have found ways to comply superficially, often through joint ventures or control arrangements that meet certification criteria but not the underlying sovereignty demands.

Historically, certifications like ISO 27001, SOC 2, and BSI C5 have focused on security practices, not jurisdiction or ownership. The emergence of the ownership cap as a formal test marks a shift toward more tangible sovereignty verification. Still, as of mid-2026, the landscape remains mixed, with some providers still not meeting the ownership standard despite holding recognized security certifications.

“Many providers are structurally circumventing sovereignty rules by creating joint ventures or control arrangements, which complicates compliance verification.”

— An industry expert familiar with French regulations

Extent of Non-Compliance and Future Enforcement

It is not yet clear how many providers will fully meet the ownership sovereignty standards in the long term, or how regulators will enforce the 24% ownership cap across international companies. The actual impact of these standards on market practices and provider structures remains developing, with some providers possibly adjusting control arrangements or seeking exemptions.

Next Steps for Providers and Regulators in Sovereignty Certification

Regulators are expected to increase scrutiny on ownership structures, with more providers pursuing SecNumCloud or similar sovereignty certifications. Companies may restructure ownership or control arrangements to comply with the 24% rule. Additionally, ongoing audits and regulatory updates will clarify enforcement and compliance standards, shaping the future landscape of European cloud sovereignty.

Key Questions

What does the 24% ownership rule mean for cloud providers?

The 24% rule limits foreign ownership to ensure legal sovereignty, meaning no single non-EU entity can hold more than 24% of voting rights, which is verified through a transparent, arithmetic check on ownership structures.

Why do certifications like ISO 27001 not guarantee sovereignty?

These certifications focus on operational security practices and do not address jurisdiction or ownership control, which are critical for sovereignty under European regulations.

Are US-based cloud providers able to meet European sovereignty standards?

Many US providers can meet security standards but face challenges with ownership caps and jurisdictional restrictions. Some create joint ventures or control arrangements to comply with the 24% rule.

What are the risks of relying on certifications alone for sovereignty?

Certifications may give a false sense of control, as they do not verify legal ownership or immunity from extraterritorial laws, which are essential for sovereignty in regulated sectors.

What is the significance of the ownership control standard for European data law?

It provides a clear, measurable metric to ensure that data is under European legal control, which is crucial for compliance with GDPR and national sovereignty requirements.

Source: ThorstenMeyerAI.com

This content is for general information only and is not financial, tax or legal advice. Consult a qualified professional for decisions about your money.
You May Also Like

Michigan Court Orders Kalshi to Stop Sports Event Contracts

A Michigan court has ordered Kalshi to cease offering contracts tied to sports events, citing regulatory concerns. The ruling impacts the emerging sports betting derivatives market.

The Safety Card, Played From Every Side: David Sacks, Anthropic, and the Fable Standoff

White House adviser David Sacks claims Anthropic refused to fix a cybersecurity jailbreak, leading to model bans. The dispute highlights safety and trust issues.

Saturation. The ten-essay framework, closed.

The ten-essay European sovereign-LLM framework is now complete, with no new structural insights expected before August 2026.

Grimfaste: Operations for a Fleet

Grimfaste introduces a new control platform for managing large publishing fleets, focusing on operational health, link integrity, and EU privacy standards.