AI And Sovereignty: Why Most Certifications Are Missing The Point

📊 Full opportunity report: AI And Sovereignty: Why Most Certifications Are Missing The Point on ThorstenMeyerAI.com — validation score, market gap, and execution plan.

TL;DR

Most industry certifications focus on security practices but do not address legal sovereignty issues. The French SecNumCloud framework introduces a unique ownership test, highlighting gaps in existing standards. This impacts data control and jurisdiction in AI and cloud services.

European cybersecurity frameworks are shifting focus from traditional security controls to legal sovereignty, exemplified by France’s SecNumCloud framework, which uniquely tests ownership control through a numerical cap. This development underscores a critical gap in existing certifications, which mainly verify security practices rather than legal control.

Current certifications such as ISO 27001, SOC 2, and BSI C5 primarily assess operational security controls—access management, encryption, incident response—aiming to verify security practices. However, they do not address the legal jurisdiction or sovereignty of data, leaving gaps in legal control, especially in cross-border contexts.

In contrast, SecNumCloud, issued by France’s ANSSI, introduces a numerical ownership cap—24%—that explicitly tests who ultimately controls the cloud provider. This requirement ensures data sovereignty by limiting foreign ownership, making it a legal sovereignty test rather than a security certification. As of mid-2026, about ten providers hold active SecNumCloud qualifications, including OVHcloud and Scaleway, with more in progress.

Meanwhile, BSI C5 incorporates jurisdiction disclosures but does not mandate immunity from extraterritorial laws like the CLOUD Act. Both standards can coexist, but SecNumCloud’s ownership test marks a significant evolution toward sovereignty-aware certifications.

At a glance
analysisWhen: ongoing, with developments as of mid-20…
The developmentA new focus on ownership and sovereignty testing in European cloud and AI certifications reveals significant gaps in traditional standards.
Crypto market snapshot
Bitcoin BTC$64,683▲ 1.2%
Ethereum ETH$1,868▲ 1.3%
Tether USDT$0.9993▼ 0.0%
BNB BNB$568.47▲ 0.1%
USDC USDC$0.9999▼ 0.0%
XRP XRP$1.1▲ 0.9%
Solana SOL$75.96▲ 1.4%
TRON TRX$0.3254▲ 1.1%
Live data · CoinGecko · alternative.me (24h change)
The 24% Rule — Insights
AI Dispatch · Insights · 16 July 2026

The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty

ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.

◆ SecNumCloud’s sovereignty test — an ownership cap, not a security control
Capital & voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. That’s it. Checkable from a cap table.
✓ QUALIFIES collective cap ✕ STRUCTURALLY INELIGIBLE
0 — 24% individual— 39% collective— 100% non-EU ownership
OVHcloud · Outscale · Scaleway · Numspot · Cloud Temple AWS · Azure · Google — structurally ineligible natively Cohere–Aleph Alpha at ~90% Canadian — ~4× over the cap ? Mistral — non-EU VC share never publicly tested
Sort the alphabet soup into two piles
Framework
What it actually tests
What it doesn’t
Ownership?
ISO 27001 / SOC 2
Security practice, controls, process
Jurisdiction. Entirely.
NO
BSI C5
Implemented controls + disclosure of place of jurisdiction. German federal baseline since 2022.
Immunity. You still document residual CLOUD Act risk in your DPIA.
NO
Gaia-X
Interoperability, portability, declared policies
It’s not a security audit — and AWS/Azure/Google are members
NO
EUCS (as drafted)
Security controls, 3 levels, mutual recognition
The “High+” sovereignty tier was stripped out. EUCS High ≠ CLOUD Act immunity.
NO
SecNumCloud
ANSSI qualification (the French State stands behind it). 360+ criteria · v3.2 · EU domicile · EU-only storage · audited key custody · the 24/39 cap
Nothing much — it’s ~10× ISO 27001’s complexity. Only ~9–10 hold it.
YES
BSI C5 — disclosure

C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.

SecNumCloud — immunity

Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.

▶ What to actually watch: CADA — the rulebook that replaces the badges

The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.

✓ The six questions to ask any vendor
1Who is your ultimate parent, and where is it incorporated?
2Will you state in writing that you’re not subject to non-EU extraterritorial law?
3What % of capital & voting rights is held by non-EU entities?
4Who holds the keys — and can you be compelled to produce them?
5Which of your certs tests ownership, and which tests practice?
6What is your CADA recognition roadmap?
If a vendor can’t answer #1 and #3 immediately, the rest of the meeting is theatre. And check the layer: sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.
The take

Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.

Sources: ANSSI (SecNumCloud v3.2, qualified-provider catalogue) via Legiscope, Scalingo, Feel Agile, SoftwareSeni; BSI & AWS compliance docs (C5, ESC C5 report, GA Jan 2026); AWS Artifact (ESC-SRF); sota.io, euCloudCost (EUCS levels, stripped sovereignty tier, DORA CTPP designations Nov 2025); CADA COM(2026) 502 via cadafaq.com; ANSSI–BSI joint statement via BSI; Cross-Border Data Forum (protectionism critique); CISPE. CADA is a proposal; EUCS is unadopted. Ownership questions are open questions from public info, not assertions of non-compliance. Not legal advice — get counsel.
thorstenmeyerai.com

Legal Sovereignty as a Certification Criterion

This shift matters because security certifications alone do not guarantee legal control over data. The introduction of sovereignty tests like SecNumCloud’s ownership cap emphasizes the importance of jurisdictional control in cloud and AI services, especially for sensitive government and critical infrastructure data. It highlights a growing recognition that legal sovereignty is as vital as technical security in data governance, impacting how organizations select and trust cloud providers.

Amazon

secure cloud storage with sovereignty features

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Limitations of Traditional Security Certifications

Most existing standards—ISO 27001, SOC 2, BSI C5—have been designed to verify security practices within operational boundaries, not legal jurisdiction. They focus on controls like encryption, access, and incident response, but do not address who ultimately controls the data or the legal environment. This gap has become more apparent as European regulators push for sovereignty measures, with France’s SecNumCloud leading the way by incorporating a numerical ownership threshold.

Historically, U.S.-based cloud providers like AWS and Microsoft have held numerous certifications but remain subject to U.S. law, such as the CLOUD Act. Their certifications do not alter jurisdictional control, prompting European regulators to develop standards that explicitly test ownership and control.

“SecNumCloud is a government-backed qualification that explicitly tests ownership and sovereignty, not just security controls.”

— Anssi official

Cuvex Personal Hardware Security Module (HSM) for Sovereign Self-Custody

Cuvex Personal Hardware Security Module (HSM) for Sovereign Self-Custody

Sovereign Self-Custody HSM: Personal hardware security module that encrypts secrets offline without relying on servers or third-party infrastructure

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Questions on Certification Effectiveness

It is still unclear how widely SecNumCloud will be adopted outside France, and whether other European countries will develop similar sovereignty tests. Additionally, the impact of these standards on international cloud providers, particularly U.S.-based firms, remains uncertain, especially regarding legal jurisdiction and compliance complexities.

Furthermore, the effectiveness of ownership caps in preventing foreign control in practice has yet to be fully evaluated, and whether this approach can be scaled across different jurisdictions is still under discussion.

Adaptive Cryptographic Access Control (Advances in Information Security, 48)

Adaptive Cryptographic Access Control (Advances in Information Security, 48)

Used Book in Good Condition

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps in Sovereignty Certification Development

Expect continued expansion of sovereignty-focused standards like SecNumCloud within Europe, potentially influencing global certification practices. More providers are likely to pursue SecNumCloud qualifications as French regulations mandate its use for sensitive public-sector data. Additionally, other European nations may develop similar frameworks, emphasizing legal control alongside security.

Regulatory agencies and industry stakeholders will monitor how these standards influence provider behavior, data governance, and cross-border data flows, shaping the future landscape of AI and cloud sovereignty.

Amazon

enterprise NAS storage for cybersecurity

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does SecNumCloud differ from traditional security certifications?

SecNumCloud explicitly tests ownership control through a numerical cap on foreign ownership—24%—making it a sovereignty test. Traditional certifications focus on security practices without addressing legal jurisdiction or control.

Can a provider with SecNumCloud certification still be subject to U.S. law?

Yes. SecNumCloud certifies legal sovereignty within the EU, but providers like AWS remain subject to U.S. laws such as the CLOUD Act, regardless of certification.

Will SecNumCloud become a standard across Europe?

It is likely to influence European cloud sovereignty policies, especially as France mandates it for sensitive data and pushes for broader adoption in critical sectors. Other countries may develop similar standards.

What challenges exist in implementing ownership caps?

Ownership caps require detailed ownership transparency and can be difficult to enforce across complex corporate structures. Scaling this approach internationally may face legal and operational hurdles.

Does certification guarantee immunity from jurisdictional laws?

No. Certifications like SecNumCloud confirm compliance with sovereignty criteria but do not exempt providers from applicable laws, especially extraterritorial ones like the CLOUD Act.

Source: ThorstenMeyerAI.com

Nothing in this article is financial or investment advice. Cryptocurrency and precious-metal investments carry significant risk — do your own research and consider a licensed advisor.
You May Also Like

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

Exploring the feasibility of SOC2 Type 2 compliance for solo entrepreneurs, including practical advice, challenges, and alternative approaches.

Multi‑Sig Wallets: Why Celebs Trust Them for Fortune‑Size Bags

Offering unmatched security and control, multi-sig wallets are the preferred choice for celebrities managing fortune-size assets—discover why they trust this technology.

The Eye Over The City: How Wide-Area Motion Imagery Works — And Where It Goes Blind

An in-depth look at how Wide-Area Motion Imagery (WAMI) works, its applications, limitations, and future integration with radar technology.

The Frameworks Can’t See the Thing That Matters: A Year of AI-Enabled Cyber Threats

A new report reveals AI is making cyber attackers more dangerous and harder to identify, challenging decades-old threat assessment methods.