AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Most AI and cloud security certifications focus on practices but do not address legal sovereignty. France’s SecNumCloud introduces a unique ownership rule limiting foreign control to 24%, highlighting gaps in existing certifications.

Most existing AI and cloud security certifications do not address the key legal sovereignty question: can a foreign government compel access to data? France’s SecNumCloud certification stands out by introducing a specific ownership threshold—24%—that tests control and sovereignty directly. This development matters because it highlights a critical gap in current certifications, which mainly verify security practices but not jurisdictional control.

While certifications like ISO 27001, SOC 2, and BSI C5 verify operational security controls—such as access management, encryption, and incident response—they do not address legal sovereignty or jurisdictional immunity. These standards confirm that a provider operates securely but do not prevent foreign laws from compelling data access, especially for providers outside the EU.

In contrast, France’s SecNumCloud qualification, created by ANSSI, explicitly incorporates a sovereignty test: ownership and voting rights held by non-EU entities must not exceed 24% individually or 39% collectively. This arithmetic cap is a direct, checkable measure of control, not just a policy or control implementation. Achieving this level of control is extremely complex—scalingo’s CEO describes it as a ’10’ on a 1-to-10 difficulty scale, compared to ISO 27001’s ‘1.’

Currently, about nine to ten providers have SecNumCloud certification, including OVHcloud and Outscale, with more in the pipeline. This certification is mandatory for hosting sensitive French public-sector data and is being pushed for broader critical infrastructure sectors.

At a glance
analysisWhen: developing; ongoing adoption and debate…
The developmentThe article explains why most AI sovereignty certifications are insufficient, emphasizing the significance of the 24% ownership rule in France’s SecNumCloud framework.

Implications of the 24% Control Limit for Cloud Sovereignty

This ownership cap fundamentally shifts the discussion from security practices to legal sovereignty. It ensures that providers cannot be controlled by outside actors beyond a strict threshold, reducing the risk of foreign governments gaining access through ownership structures. For European public and private sectors, this enhances data sovereignty and compliance with EU laws, especially amid increasing geopolitical tensions and extraterritorial legal claims.

However, it also exposes the limitations of traditional certifications, which do not address jurisdictional immunity, leaving gaps for providers that hold multiple certifications but remain under foreign jurisdiction. The 24% rule thus introduces a new standard for sovereignty, which could influence procurement and regulatory policies across Europe and beyond.

Amazon

AI sovereignty certification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Limitations of Existing Certifications in Addressing Sovereignty

Most security standards—ISO 27001, SOC 2, BSI C5—focus on operational security controls, assessing whether providers run data centers and processes securely. They do not evaluate ownership, jurisdiction, or legal control, which are critical for sovereignty. For example, BSI C5 includes controls on jurisdiction disclosures but does not require immunity from non-EU laws, meaning providers can still be subject to laws like the US CLOUD Act.

French SecNumCloud, introduced in 2016 and now in its third version, diverges by requiring legal sovereignty measures—EU domicile, data storage, audited key custody, and the ownership cap—making it a qualification backed by government standing, not just an audit opinion. This shift reflects a broader recognition that security controls alone are insufficient for sovereignty.

US hyperscalers, unable to meet the ownership threshold directly, have created joint ventures and control structures that comply with the 24% rule, effectively circumventing the limitations of existing certifications while maintaining US jurisdictional ties.

“The 24% ownership rule is the only test that directly measures control and sovereignty, not just security practices.”

— Thorsten Meyer

Amazon

data sovereignty hardware security module

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Remaining Questions About Implementation and Adoption

It is still unclear how widely the 24% ownership rule will be adopted outside France or how other European countries might incorporate similar measures. The actual enforcement and compliance process for joint ventures or control structures designed to meet the threshold remain complex and untested at scale. Additionally, how this framework interacts with global legal standards and whether it will influence international cloud procurement policies is still evolving.

Amazon

cloud data ownership control device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Future Developments in Sovereignty Certification Standards

Expect further adoption of SecNumCloud among European providers, especially those handling sensitive data. Regulatory bodies may develop similar sovereignty tests, and international discussions could emerge on integrating ownership controls into global standards. Monitoring how US and non-EU providers adapt control structures to meet sovereignty thresholds will be key in the coming months and years.

Amazon

secure data storage for government

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What exactly is the 24% ownership rule?

The 24% ownership rule limits the individual ownership stake of non-EU entities in a provider to no more than 24%, or 39% collectively, as a direct measure of control and sovereignty.

Does a certification like C5 or ISO 27001 guarantee sovereignty?

No. These standards verify operational security practices but do not address jurisdictional control or immunity from foreign laws. SecNumCloud’s ownership rule is designed specifically to address sovereignty.

Why is achieving SecNumCloud certification so difficult?

Because it requires complex ownership and control structures to stay within the 24% threshold, which involves intricate legal, corporate, and operational arrangements, making it significantly more challenging than traditional security standards.

Will this ownership rule impact US cloud providers?

Yes. US providers seeking to meet French and broader European sovereignty standards must restructure control and ownership, often via joint ventures or control arrangements, to comply with the 24% cap.

Source: ThorstenMeyerAI.com

You May Also Like

The Privacy Impact Assessment Trigger List You Actually Need

For those handling sensitive data or implementing new systems, understanding the Privacy Impact Assessment trigger list is crucial to avoid overlooked risks.

Micro-Cut vs Cross-Cut Shredders: Which Security Level Fits Your Office?

Getting the right shredder depends on your security needs and workflow, but which option truly offers the best protection for your office?

Badge Systems, Biometric Locks, and Audit Trails Explained

Just understanding how badge systems, biometric locks, and audit trails integrate can reveal the key to unbeatable security—find out how they work together.

Subprocessor Reviews Are Too Weak at Most Companies

By neglecting thorough subprocessor reviews, most companies leave critical risks unaddressed, risking compliance failures and security breaches that demand urgent attention.