🎙️ Episode 33905:57 • July 31, 2026
AI Agent Identity: Why Cyera Paid $1B for Oasis in 2026
Listen to this episode
AI-generated discussion by Alex and Jamie
About this episode
Join Alex and Jamie on this thrilling episode of "Nerd Level Tech AI Cast" as they unravel the seismic implications of Cyera's jaw-dropping $1 billion acquisition of Oasis Security. Discover the urgent need for agentic access management in a world where AI identities outnumber human ones, and learn why traditional security measures may no longer keep the chaos at bay. Tune in for laughs, insights, and a deep dive into the rapidly evolving landscape of AI security!
Transcript
[Alex]: Welcome back to "Nerd Level Tech AI Cast," where we dive deep into the code, the chaos, and the occasional coffee spill powering the AI security world. I’m Alex— [Jamie]: —and I’m Jamie, here to ask the burning questions, make the bad puns, and keep Alex from explaining zero-knowledge proofs at parties. [PAUSE] So, Alex, what’s on the docket today? [Alex]: Well, Jamie, today we're talking about a billion-dollar bet. Cyera—big name in data security—just signed a $1 billion letter of intent to acquire Oasis Security. And nope, that's not a typo. One. Billion. Dollars. [PAUSE] [Jamie]: [Whistles] If I had a buck for every time someone said “AI security” was the next big thing, I’d... well, I wouldn’t have a billion, but maybe I could buy lunch. What’s so special about this Oasis company? [Alex]: Great question. Oasis does something called “agentic access management.” Basically, they help companies keep track of, and control, all the AI agents and machines running in their systems. And that’s suddenly a huge deal, because for every human identity in a company, there are now 109 machine identities. That’s up from 82 last year! [Jamie]: Wait—109 bots per person? So, for every employee, there’s an army of AI minions running around? [PAUSE] That sounds... both awesome and terrifying. [Alex]: Pretty much. And here’s the kicker: only 37% of organizations can actually revoke an AI agent’s credentials if something goes wrong. So if an agent goes rogue, you might not even be able to pull the plug. [Jamie]: So, it’s like giving your Roomba the keys to the office, but you forgot how to lock the doors? [Alex]: [Laughs] Exactly. Except your Roomba might chain credentials and access your payroll data while it’s at it. [Jamie]: [Groans] So this is why companies are throwing big money at identity security for AI agents. But why can’t we just use the same identity systems as we do for people? [Alex]: Ah, that’s the problem. Traditional identity and access management—IAM—was built for humans: you hire someone, you give them access, you take it away when they leave. AI agents? They pop up for a task, act on behalf of users or themselves, sometimes spawn sub-agents, and may only exist for a few minutes. IAM just wasn’t built for that kind of chaos. [PAUSE] [Jamie]: So they’re like digital mayflies—here one moment, gone the next, but with access to your cloud database? [Alex]: You nailed it. And the result is what security nerds call a “governance gap.” Companies built and deployed agents faster than they built the systems to manage them. Now, security is scrambling to catch up. [Jamie]: And Cyera’s solution to this? Buy Oasis instead of building everything themselves? [Alex]: Yep. It’s a classic “merge, not an add-on.” Cyera classifies data, Oasis classifies identities. Their CEO even said, “Knowing your data isn’t enough if you can’t govern who or what touches it.” So, they’re connecting the dots between what data you have and which agents—or humans—can see it. [Jamie]: [PAUSE] This isn’t just a Cyera thing, right? I read something about Cisco, CrowdStrike, and even Palo Alto getting in on the AI identity action. [Alex]: You’ve been doing your homework! It’s a full-on consolidation wave. Just in 2026, three major acquisitions focused on agent and non-human identity—worth over $2 billion combined. Companies from networking, endpoint security, even certificates—everyone’s realizing identity is the new control plane for AI agents. [Jamie]: You almost make it sound like the security industry’s version of Pokémon: gotta catch ’em all—except it’s AI agents and their credentials. [Alex]: [Laughs] That’s… not wrong. And if you don’t catch ’em, your data—and maybe your reputation—are on the line. [Jamie]: All right, but let’s get practical. What can companies actually do now, short of spending a billion dollars? [Alex]: Start with inventory. You can’t govern what you can’t see. List out all your agents—SaaS bots, cloud-hosted AIs, code tools, everything. Then, make sure every agent has its own unique identity. No more shared service accounts, no more bots borrowing a human’s credentials. [Jamie]: So, no more “everyone shares the admin password because Steve’s on vacation”? [Alex]: Exactly. [PAUSE] And, if you’re feeling fancy, look into the new standards that are coming out. The IETF has a draft on Agent Identity Management Systems—AIMS—and NIST is working on guidelines too. The industry is moving fast, but even basic best practices—like short-lived credentials and proper audit logs—can close a lot of the gap. [Jamie]: And maybe, just maybe, don’t let your AI agents chain credentials like they’re on a shopping spree. [Alex]: Right. Credential chaining is how a lot of recent breaches happened—agents finding and using credentials they were never supposed to have. Guardrails and monitoring are key. [Jamie]: Final question, Alex: If you could give one take-home message to our listeners, what would it be? [Alex]: Treat every AI agent like a coworker with their own badge. If you wouldn’t let a random intern run wild in your data center, don’t let your agents do it either. Give them just enough access, and always be ready to yank their credentials if something goes weird. [Jamie]: And maybe buy your security team lunch for keeping up with all those identities. They’ve earned it. [Alex]: They really have. [PAUSE] That’s it for today’s episode of "Nerd Level Tech AI Cast." Thanks for nerding out with us! [Jamie]: Don’t forget to subscribe, send us your best AI agent mishap stories, and as always—keep your credentials short-lived and your coffee strong. [Alex]: See you next time! [OUTRO MUSIC FADES OUT]