TL;DR
A widely cited analysis published July 16, 2026 argues that mainstream cloud and AI certifications — ISO 27001, SOC 2, BSI C5, Gaia-X — verify security practices but say nothing about whether a foreign government can compel access to customer data. Only France’s SecNumCloud framework tests ownership directly, capping non-EU capital and voting rights at 24% individually and 39% collectively. The question is gaining urgency as the proposed EU Cloud and AI Development Act (CADA) moves through Brussels with sovereignty levels for public procurement.
A new analysis of European cloud and AI certification schemes argues that every widely displayed compliance badge — ISO 27001, SOC 2 Type II, BSI C5 and Gaia-X membership — fails to answer the question that decides regulated-industry deals: can a foreign government compel access to the data. The report, published July 16, 2026 by Thorsten Meyer AI, points to France’s SecNumCloud framework as the only European scheme that tests that question directly — not with a security control, but with an ownership cap of 24 percent. The argument lands as Brussels weighs the proposed Cloud and AI Development Act (CADA), which would introduce Union-wide sovereignty assurance levels for public procurement.
The core of the analysis is a mechanical test. Under SecNumCloud version 3.2, administered by France’s ANSSI, capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The check is performed from a provider’s cap table, not from its security documentation. According to the report, OVHcloud, Outscale, Scaleway, Numspot and Cloud Temple qualify, while AWS, Microsoft Azure and Google Cloud are structurally ineligible in their native form — which is why Google partnered with Thales on S3NS and Microsoft with Capgemini and Orange on Bleu to create structures that can meet the bar. Only around nine to ten providers currently hold the qualification, which the report describes as roughly ten times the complexity of ISO 27001.
The analysis sorts the certification landscape into two categories. ISO 27001, SOC 2, BSI C5 and the draft EUCS certify practice — access controls, encryption, incident response — and explicitly do not test jurisdiction or ownership. BSI C5 does require disclosure of the place of jurisdiction, meaning residual exposure to laws such as the US CLOUD Act must still be documented in a data protection impact assessment. The still-unadopted EUCS scheme had its proposed ‘High+’ sovereignty tier stripped during drafting, the report notes, so even its highest level does not confer immunity from non-EU law.
The report also flags open ownership questions. The proposed Cohere–Aleph Alpha tie-up would sit at roughly 90% Canadian ownership — about four times over the cap — while Mistral’s non-EU venture capital share has never been publicly tested against the threshold. The author stresses these are open questions from public information, not assertions of non-compliance.
The 24% rule: why most “sovereign cloud” certifications don’t test sovereignty
ISO 27001. SOC 2. BSI C5. Gaia-X. Every badge real, audited, correctly displayed — and not one answers the question that decides the deal: can a foreign government compel your data? Exactly one European framework tests that. It does it with a number.
C5 does cover place of jurisdiction, data location & disclosure obligations. It requires you to declare which law reaches you. C5 tells you the gun is in the room.
Requires that no non-EU law can reach you at all — enforced by the ownership cap. SecNumCloud requires there be no gun. That’s the whole difference.
The proposed Cloud and AI Development Act (COM(2026) 502) would set four Union assurance levels for public procurement. Its own recitals concede the point: Cybersecurity Act certification “is not suited for addressing sovereignty concerns.” National labels won’t be banned — but a SecNumCloud provider would still need separate Article 17 recognition. If it passes, the badge on the vendor’s website stops mattering and the assurance level starts. Meanwhile ANSSI + BSI have jointly committed to common criteria specifying where failure is disqualifying.
Microsoft showed the gap better than any critic: May 2025 — encryption makes access “technically impossible.” One month later — cannot guarantee immunity from US authorities. Thirty days between the marketing and the law. SecNumCloud doesn’t ban American technology — it forces a change of control over it (hence S3NS = Thales+Google, Bleu = Capgemini+Orange on Azure). Is it also protectionism? Partly, yes — and that critique is exactly why EUCS High+ died. Both things are true. Don’t ask if a provider is “sovereign” — the word has been marketed into meaninglessness. Ask the arithmetic: who owns you, and what law reaches you? Then check whether the answer is above or below 24% — including for the European champions nobody has asked.
Why Ownership Caps Now Outrank Security Badges
For buyers in regulated European sectors — banking under DORA, healthcare, defense, public administration — the distinction between practice and ownership determines whether a procurement survives legal review. A provider can hold every mainstream certification and still be subject to extraterritorial US law, meaning customer data stored in European data centers can remain reachable by foreign authorities. The report frames this as a structural gap that no audit of security controls can close, because the risk sits in corporate control, not in how servers are run.
The stakes are rising because the proposed CADA regulation (COM(2026) 502) would shift the market from voluntary badges to four Union assurance levels tied to public procurement. If adopted, the label on a vendor’s website would matter less than its recognized assurance level — potentially redrawing the competitive map for American hyperscalers, their European joint ventures, and homegrown providers. The debate also carries a protectionism charge: critics cited in the report, including the Cross-Border Data Forum, argue ownership caps double as industrial policy, a tension the analysis credits with helping kill the EUCS ‘High+’ tier.
European cloud sovereignty certification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Microsoft’s May 2025 Reversal Framed the Debate
The sovereignty argument gained concrete form in mid-2025, when Microsoft told European audiences that encryption rendered foreign access to customer data ‘technically impossible’ — then acknowledged roughly a month later, under questioning in France, that it could not guarantee immunity from US authorities. The thirty-day gap between the marketing claim and the legal position became a reference point for skeptics of certification-based assurances.
European regulators have been building alternatives for years. BSI’s C5 has been the German federal baseline since 2022 and requires disclosure of applicable jurisdiction. Gaia-X promotes interoperability and portability but counts AWS, Microsoft and Google among its members and is not a security audit. EUCS, drafted under the Cybersecurity Act, remains unadopted after its sovereignty tier was removed. Against that backdrop, ANSSI and BSI have jointly committed to developing common criteria specifying where failure is disqualifying — a signal that the two largest national schemes are converging ahead of CADA.
“C5 tells you the gun is in the room. SecNumCloud requires there be no gun.”
— Thorsten Meyer AI, on the difference between BSI C5 and SecNumCloud
![[By Jocko Willink ] Extreme Ownership: How U.S. Navy SEALs Lead and Win (Hardcover)【2018】by Jocko Willink (Author) (Hardcover)](https://m.media-amazon.com/images/I/41ggaLUnBUL._SL500_.jpg)
[By Jocko Willink ] Extreme Ownership: How U.S. Navy SEALs Lead and Win (Hardcover)【2018】by Jocko Willink (Author) (Hardcover)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Which Provider Cap Tables Remain Unexamined
Several points in the debate are unresolved. Mistral’s non-EU venture capital share has never been publicly tested against the 24/39 thresholds, and the report frames this — along with the Cohere–Aleph Alpha structure — as open questions from public information, not findings of non-compliance. The protectionism critique is also live: whether ownership caps are a legitimate security measure or industrial policy dressed as one remains disputed, and that argument previously proved strong enough to strip the EUCS ‘High+’ sovereignty tier.
On the regulatory side, CADA is only a proposal and could be amended or delayed; whether national labels like SecNumCloud would need separate recognition under its Article 17 process is not settled. The analysis itself is one firm’s reading of the frameworks — it is not legal advice, and buyers are advised to seek counsel before acting on it.
cloud provider ownership structure analysis
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
CADA Deliberations and Joint ANSSI-BSI Criteria
The next milestones are legislative and technical. The Cloud and AI Development Act will move through the European Parliament and Council, where its four assurance levels and their link to public procurement will be negotiated; the report predicts the framework will be the field ‘everyone will be arguing about by 2027.’ In parallel, ANSSI and BSI are expected to deliver on their joint commitment to common criteria defining disqualifying failures — work that could harmonize how ownership is tested across the two largest national schemes.
For procurement teams, the report recommends acting before the rules settle: ask vendors for their ultimate parent and place of incorporation, the percentage of capital and voting rights held by non-EU entities, who holds the encryption keys, and a CADA recognition roadmap — and to check each layer of the stack, since sovereign infrastructure under a non-EU-controlled SaaS layer is not a sovereign stack.

Privacy by Design: Design and Build Your Own Privacy-First Applications
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is the 24% rule in SecNumCloud?
It is an ownership test in France’s SecNumCloud cloud-security qualification: capital and voting rights held by companies not based in the EU must not exceed 24% individually or 39% collectively. The check is done from the provider’s cap table and is designed to prevent non-EU control that could expose data to foreign laws such as the US CLOUD Act.
Don’t ISO 27001 or SOC 2 already guarantee data sovereignty?
No. According to the analysis, those certifications audit security practice — access controls, encryption, incident response — and say nothing about jurisdiction or ownership. A fully certified provider can still be legally compelled by a foreign government to produce data or keys.
Can AWS, Microsoft or Google ever qualify under SecNumCloud?
Not in their native corporate form, because of their US ownership. The report notes they can participate through European-controlled joint ventures — Google with Thales on S3NS, and Microsoft with Capgemini and Orange on Bleu — structured so that control sits below the ownership caps.
What is the Cloud and AI Development Act (CADA)?
CADA, formally COM(2026) 502, is a proposed EU regulation that would create four Union assurance levels for cloud and AI services used in public procurement. Its recitals state that Cybersecurity Act certification is not suited to addressing sovereignty concerns. It remains a proposal and has not been adopted.
What should buyers ask cloud vendors about sovereignty?
The report’s checklist includes: who is the ultimate parent and where is it incorporated; what percentage of capital and voting rights is held by non-EU entities; who holds the encryption keys and whether they can be compelled to produce them; which certifications test ownership versus practice; and what the vendor’s CADA recognition roadmap is.
Source: Thorsten Meyer AI