AI Agent Identity: Why Cyera Paid $1B for Oasis in 2026
July 30, 2026

In one line: AI agent identity is the practice of treating every autonomous agent as its own named, credentialed, revocable principal — a subclass of non-human identity (NHI) that now dominates enterprise identity counts and, as of July 2026, commands billion-dollar acquisition prices.
TL;DR: On July 28, 2026, data-security company Cyera signed a letter of intent to acquire Oasis Security for approximately $1 billion, mostly in cash.12 Oasis builds what it calls "agentic access management" — inventory, ownership, and control for machine and agent identities.2 The price makes sense against two numbers from Palo Alto Networks' 2026 Identity Security Landscape: organizations now run 109 machine identities for every human identity, up from 82:1 a year earlier, and only 37% can revoke an AI agent's credentials.34 Enterprises deployed agents faster than they built the identity layer to govern them, and the security industry is now buying that layer rather than building it.
What You'll Learn
- What Cyera is actually acquiring, and what "agentic access management" means
- The 109:1 machine-to-human identity ratio, and why traditional IAM breaks on agents
- The 2026 identity-security consolidation wave, deal by deal
- What survey data says enterprises still cannot do with their agent fleets
- Which standards are racing to fill the gap — IETF AIMS and NIST's NCCoE paper
- A practical checklist if you are shipping agents into production now
What Cyera is actually buying
The deal is a letter of intent, not a closed transaction — a distinction worth holding onto, since regulatory clearance and definitive terms still follow.1
Cyera announced it on July 28, 2026. The consideration is majority cash, with the remainder in Cyera shares; Israeli outlet Calcalist put the cash portion at roughly $700 million.2
Oasis Security was founded in 2022 by Danny Brickman and Amit Zimerman and has raised about $195 million, including a $120 million Series B led by Craft Ventures in March 2026 with Cyberstarts, Sequoia Capital, and Accel participating.2
Its product category is non-human identity. In Cyera's own description, Oasis covers "inventory, ownership, access, and control for every machine and agent identity" — the enumeration problem before the enforcement problem.5
Cyera itself was founded in 2021 by CEO Yotam Segev and CTO Tamar Bar-Ilan, has raised roughly $2.3 billion in total, and recently closed a $600 million round at a $12 billion valuation.12 Oasis is its third acquisition of 2026, after Ryft and Genie Security.1
The strategic logic is a merge, not an add-on. Cyera classifies data; Oasis classifies identities. Segev's framing in the announcement is that neither half works alone: "Knowing your data isn't enough if you can't govern who or what touches it. Knowing your identities isn't enough if you don't know what they can see."5
Why non-human identity became the bottleneck
The number driving this market is not a projection. It is a measurement.
Palo Alto Networks surveyed more than 2,900 cybersecurity decision-makers for its 2026 Identity Security Landscape, published in May 2026. It found an average of 109 machine identities per human identity — up from 82:1 the year before, a 33% jump in the ratio itself.34
The composition matters more than the total. Non-human identity used to mean API keys and certificates; now 99% of organizations have adopted AI agents, and 40% of those agents already have access to organizational data.4
And the curve is still steepening: 77% of organizations expect the machine-identity count to keep climbing.4
The control side has not kept pace. In the same report, only 37% of organizations can revoke an AI agent's credentials, and only 30% have immutable audit logging for what those agents do.4
That is the gap Cyera just paid $1 billion to close. Nearly two-thirds of enterprises have deployed a class of autonomous software they cannot switch off at the identity layer.
Palo Alto's own framing of the urgency is worth quoting: its Unit 42 incident response data shows AI-assisted attacks moving from initial access to exfiltration in 25 minutes.4 A credential rotation policy measured in hours does not survive that math.
Cyera's own pitch for the acquisition cites a sharper figure: non-human identities inside Fortune 500 companies grew "nearly 500% in the last six months alone."5 That is a vendor number from the acquiring company, so treat it as directional rather than independently audited — but it points the same way as the Palo Alto survey.
The reason this breaks traditional IAM is structural, not a matter of configuration. Human identity management assumes a stable principal: provisioned at hire, adjusted incrementally, de-provisioned at departure.
An agent violates every one of those assumptions. It may act in a user's name one moment and as an independent principal the next, spawn sub-agents that inherit credential context, and chain tool calls across cloud APIs, SaaS platforms, and databases in a single run — each step needing its own authorization decision.6
Writing in ISACA's Industry News in December 2025, AWS architect Vatsal Gupta framed this as a categorical mismatch rather than a configuration problem — a structural incompatibility between legacy IAM assumptions and agentic operating patterns.7
The 2026 identity-security consolidation wave
Cyera–Oasis is not an isolated bet. It is the latest move in a run of identity acquisitions that have been framed more and more explicitly around AI agents.
| Date | Acquirer → Target | Value | Focus |
|---|---|---|---|
| Oct 2024 | CyberArk → Venafi | ~$1.54B | Certificate / machine identity8 |
| Jan 8, 2026 (announced) | CrowdStrike → SGNL | $740M | Context-aware authorization for human, non-human, and agent identities9 |
| Feb 11, 2026 (closed) | Palo Alto Networks → CyberArk | ~$25B | Privileged access + machine identity10 |
| Jun 29, 2026 (closed) | Cisco → Astrix Security | ~$400M (reported) | Non-human identity and AI agent security1112 |
| Jul 28, 2026 (LOI) | Cyera → Oasis Security | ~$1B | Agentic access management12 |
Two things stand out.
First, the pace. Excluding the Palo Alto–CyberArk megadeal — which was announced in July 2025 and closed February 11, 2026 as the largest transaction in the security industry's history — three separate acquisitions aimed at agent and non-human identity were announced in 2026 alone, worth roughly $2.1 billion combined.9111 The CrowdStrike–SGNL deal was still pending as of its announcement, with closing expected in CrowdStrike's fiscal 2027 first quarter.9
Second, most of these buyers came to identity from somewhere else. Cisco's core business is networking; Cyera's is data security. CrowdStrike, which grew up in endpoint, is furthest along — it already runs a Falcon identity product line and framed SGNL as an extension of it.9 The common thread is that identity has become the control plane for AI agents, and buying that capability beat building it.
Cisco said the quiet part out loud in its acquisition post: agents are "an entirely new class of coworker," and Astrix secures "the very credentials that AI Agents are now using (and abusing) to gain access and execute work at scale."11
What enterprises still cannot do
The acquisition math rests on a governance gap that several separate surveys, published between January and May 2026, measure the same way.
| Finding | Figure | Source |
|---|---|---|
| Not confident legacy IAM can manage AI and NHI risk | 92% | CSA / Oasis Security, pub. Jan 2026 (n=383)613 |
| No documented policy for creating or removing agent identities | 78% | CSA / Oasis Security, pub. Jan 2026613 |
| Reported confirmed or suspected AI agent security incidents in the prior year | 88% | Gravitee, Feb 2026 (n=900+)14 |
| Treat agents as independent, identity-bearing entities | 22% | Gravitee, Feb 202614 |
| Cannot clearly distinguish AI agent activity from human activity | 68% | CSA / Aembit, Jan 2026 (n=228)15 |
| Say agents often receive more access than necessary | 74% | CSA / Aembit, Jan 202615 |
| Can revoke an AI agent's credentials | 37% | Palo Alto Networks, May 2026 (n=2,900+)4 |
| Have immutable audit logging for agent actions | 30% | Palo Alto Networks, May 20264 |
| Can control agent actions with proper guardrails and live monitoring | 24% | Cisco AI Readiness Index11 |
One caveat on the top two rows: the CSA/Oasis report was published in January 2026, but its fieldwork ran in August and September 2025.13 It is the oldest data in the table.
There is a detail in that table worth pausing on. The 92% figure — the single cleanest statement of the problem Cyera is buying its way into — comes from a Cloud Security Alliance survey commissioned by Oasis Security itself.613
That is not a criticism; vendor-commissioned research is standard practice, and CSA ran the analysis. But it is worth noting that the market thesis and a chunk of the market evidence here share a sponsor.
The Gravitee data comes from a different direction and lands in the same place. Beyond the 88% incident rate, its survey of more than 900 executives and practitioners found that on average only 47.1% of an organization's AI agents are actively monitored or secured, and 45.6% of teams still rely on shared API keys for agent-to-agent authentication.14
Meanwhile the CSA/Aembit survey found 85% of organizations already running agents in production — 43% still authenticate them with shared service accounts, and 31% let agents operate under a human user's identity.15
Borrowed, over-scoped, long-lived credentials are the common denominator. They also show up in the evaluation that ended in the Hugging Face breach disclosed earlier this month — a controlled red-team test rather than a production deployment, but one where the agent chained credentials it found into access it was never granted. That chaining pattern is what enterprises running agents on shared service accounts are exposed to by default.
The standards racing to catch up
Commercial consolidation is running ahead of the protocols, but the standards work is real and moving fast.
The most concrete artifact is an IETF Internet-Draft, draft-klrc-aiagent-auth, first published March 2, 2026 and revised twice since — revision -02 landed June 1, 2026.16
It defines an Agent Identity Management System (AIMS): a model of the functions needed to establish, maintain, and evaluate an agent workload's identity and permissions.16
Its thesis is deliberately conservative. Rather than minting new protocols, it leans on existing ones — WIMSE (Workload Identity in Multi-System Environments) and OAuth 2.0 — and treats AI agents as workloads. That keeps migration costs down for organizations already invested in workload identity.16
The author list is its own signal of where the industry has landed. The draft started with contributors from Defakto Security, AWS, Zscaler, and Ping Identity; later revisions added authors from OpenAI and Okta.16
NIST's National Cybersecurity Center of Excellence published a companion concept paper on February 5, 2026, Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization. Its public comment period closed on April 2, 2026.17
NIST's starting premise is the one Cyera is buying: AI agents should be identifiable entities inside enterprise identity systems, not anonymous automation running under shared credentials.17
The through-line is the same principle the standards bodies and the commercial platforms converged on separately: an agent needs an identity of its own, with short-lived credentials, so access can be scoped and revoked.
That is the connective tissue between this market and the containment and kill-switch designs that dominated agent-security discussion this month, and the cryptographic agent identity experiments running alongside them.
What to do if you are shipping agents now
You do not need a $1 billion platform to close most of this gap. The surveys point at a consistent, unglamorous sequence.
- Inventory first. You cannot govern agents you cannot enumerate. Cover SaaS-embedded agents, cloud-hosted autonomous agents, coding tools with infrastructure access, and orchestration frameworks that spawn agents dynamically.
- Give every agent its own identity. Not a shared service account, not a human's credentials. One named principal per agent, with an owning team and a human sponsor recorded.
- Replace static credentials with short-lived ones. OAuth 2.0 on-behalf-of flows for agents acting for a user; SPIFFE/SPIRE SVIDs for autonomous agents. Static API keys do not expire and cannot be scoped to a task.
- Scope permissions to the task, not the role. Zero standing privilege and just-in-time access are the patterns the identity-security field has converged on for agents.
- Write the lifecycle policy. Approval workflow to provision, required registry attributes, expiration date, and a de-provisioning trigger. Seventy-eight percent of organizations have none.613
- Rehearse revocation. Test that you can kill an agent's credentials without breaking dependent systems — before you need to.
Every item on that list is cheaper to build in than to retrofit after an incident.
Bottom line
The interesting thing about a $1 billion price on a startup founded in 2022 is not the number. It is what the number implies about sequencing.
Enterprises shipped agents into production first and figured out identity second — 85% are running agents live, 22% treat them as identity-bearing entities, and 37% can revoke an agent's credentials.14154 That gap is now large enough, and closing it is now urgent enough, that endpoint vendors, network vendors, and data-security vendors are all paying billions to acquire it rather than wait to build it.
The practical lesson for anyone deploying agents is smaller and cheaper than the headline. Name every agent, credential it individually, expire the credential, and make sure you can revoke it. The industry is spending billions to sell you that capability. Most of it you can start enforcing this quarter.
Footnotes
-
Marina Temkin, "Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents," TechCrunch, July 28, 2026. https://techcrunch.com/2026/07/28/cyera-agrees-to-acquire-oasis-security-for-1b-to-safeguard-proliferating-ai-agents/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Meir Orbach, "Cyber unicorn Cyera acquires Oasis Security in $1 billion deal," Calcalist (CTech), July 28, 2026. https://www.calcalistech.com/ctechnews/article/8115vtsb5 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Palo Alto Networks, 2026 Identity Security Landscape (survey of 2,900+ cybersecurity decision-makers worldwide), May 2026. https://www.paloaltonetworks.com/idira/idira-identity-security-landscape — see also Help Net Security coverage, May 14, 2026: https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/ ↩ ↩2 ↩3
-
Peter Beardmore and Uzi Ailon, "How to Assess Maturity When Machine Identities Outnumber Humans 109:1," Palo Alto Networks Blog, May 20, 2026 — citing the 2026 Identity Security Landscape Report (109:1 ratio up from 82:1; 77% of organizations expecting further growth; 99% AI agent adoption; 40% of agents with data access; 37% credential revocation capability; 30% immutable audit logging) and the Unit 42 Incident Response Report (25-minute access-to-exfiltration). https://www.paloaltonetworks.com/blog/identity-security/assess-maturity-when-machine-identities-outnumber-humans-1091/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Yotam Segev, "One Platform to Secure the Agentic Enterprise," Cyera blog, July 28, 2026. https://www.cyera.com/blog/one-platform-to-secure-the-agentic-enterprise ↩ ↩2 ↩3
-
Cloud Security Alliance AI Safety Initiative, "AI Agent Identity Crisis: Standards Emerge as Enterprises Lag," March 18, 2026 (updated May 20, 2026), which summarises the CSA/Oasis Security survey and the structural argument for why legacy IAM fails agentic workloads. https://labs.cloudsecurityalliance.org/research/csa-research-note-okta-ai-agent-iam-framework-enterprise-gap/ — figures drawn from this note have been re-verified against their primary sources, cited separately below. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Vatsal Gupta, "The Looming Authorization Crisis: Why Traditional IAM Fails Agentic AI," ISACA Industry News, December 19, 2025. https://www.isaca.org/resources/news-and-trends/industry-news/2025/the-looming-authorization-crisis-why-traditional-iam-fails-agentic-ai ↩ ↩2
-
CyberArk, "CyberArk Completes Acquisition of Machine Identity Management Leader Venafi," October 2024. https://www.cyberark.com/press/cyberark-completes-acquisition-of-machine-identity-management-leader-venafi/ ↩
-
CrowdStrike, "CrowdStrike to Acquire SGNL to Transform Identity Security for the AI Era," January 8, 2026. https://www.crowdstrike.com/en-us/press-releases/crowdstrike-to-acquire-sgnl-to-transform-identity-security-for-ai-era/ ↩ ↩2 ↩3 ↩4
-
"Palo Alto Networks Closes $25B Acquisition of Identity Security Company CyberArk," GovConWire, February 2026 (transaction closed February 11, 2026). https://www.govconwire.com/articles/palo-alto-networks-cyberark-25b-acquisition ↩ ↩2
-
Peter Bailey, "Securing the Agentic Workforce: Cisco Announces Intent to Acquire Astrix Security," Cisco Blogs, May 4, 2026, updated June 29, 2026 to confirm completion. Includes Cisco AI Readiness Index figures. https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security ↩ ↩2 ↩3 ↩4
-
"Cisco acquires AI security startup Astrix for $400 million," Calcalist (CTech), 2026. https://www.calcalistech.com/ctechnews/article/dy5obf581 ↩
-
Cloud Security Alliance and Oasis Security, "The State of Non-Human Identity and AI Security," press release January 27, 2026. Survey commissioned by Oasis Security and conducted online by CSA in August and September 2025, n=383 IT and security professionals. https://cloudsecurityalliance.org/press-releases/2026/01/27/79-of-it-pros-feel-ill-equipped-to-prevent-attacks-via-nhi-csa-oasis-survey-finds ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Jorge Ruiz, "State of AI Agent Security 2026 Report: When Adoption Outpaces Control," Gravitee, February 4, 2026 — survey of 900+ executives and technical practitioners (88% incident rate; 21.9% treat agents as independent identities, rounded to 22% in Gravitee's own summary; 47.1% of agents actively monitored or secured; 45.6% using shared API keys for agent-to-agent authentication). https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control ↩ ↩2 ↩3 ↩4
-
Cloud Security Alliance and Aembit, "The Identity and Access Gaps in the Age of Autonomous AI," survey conducted January 2026 (n=228), published March 24, 2026. https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions ↩ ↩2 ↩3 ↩4
-
IETF, "AI Agent Authentication and Authorization," Internet-Draft
draft-klrc-aiagent-auth—-00published March 2, 2026;-01March 30, 2026;-02June 1, 2026. Authors include P. Kasselman (Defakto Security), J. Lombardo (AWS), Y. Rosomakho (Zscaler), B. Campbell (Ping Identity), with N. Steele (OpenAI) and A. Parecki (Okta) added in later revisions. https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/ ↩ ↩2 ↩3 ↩4 ↩5 -
NIST National Cybersecurity Center of Excellence, "Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization," concept paper, February 5, 2026; public comment period closed April 2, 2026. https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd — project page: https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization ↩ ↩2 ↩3


