
Cyera's $1B acquisition of Oasis Security targets the critical challenge of securing AI agents in the enterprise by combining data security leadership with agent-specific identity protection.
Enterprise security has a new frontier: the AI agent. As businesses race to deploy autonomous agents for everything from customer service to code generation, the security industry is scrambling to keep up. Cyera’s $1 billion acquisition of Oasis Security represents the largest bet yet on solving the unique identity and data security challenges that AI agents bring.
According to a McKinsey Global Survey on AI, 78% of enterprises are expected to deploy AI agents by 2027. This explosive growth—a 300% increase in adoption from 2024 to 2026—has created a critical blind spot for Chief Information Security Officers (CISOs). Traditional identity and access management (IAM) solutions simply weren’t built for machines acting autonomously on behalf of humans. They require a fundamentally new approach.
AI agents are not simple chatbots. They are autonomous programs that execute complex tasks, interact with multiple APIs, and routinely access sensitive corporate data to get their jobs done. Unlike humans, these agents operate at machine speed, generating thousands of identity requests per minute. This capability creates a massive identity crisis for the modern enterprise.
The number of non-human identities—including API keys, service accounts, OAuth tokens, and now AI agents—has not just grown, but has outpaced human identities in most large enterprises. Traditional identity governance assumes a human is behind every credential request. This assumption breaks down entirely when a compromised AI agent can exfiltrate terabytes of data before a security team can even log into their console.
Beyond identity management, agents consume and generate vast amounts of data. Understanding precisely what data an agent is authorized to access, how it uses that data, and where that processed data ultimately ends up is a problem that inherently requires a Data Security Posture Management (DSPM) strategy. This is Cyera’s home turf and core competency.
The convergence of these two critical challenges—non-human identities and data security—is what made the combination of Cyera and Oasis not just sensible, but inevitable. The $1 billion price tag reflects the urgency of the problem in an increasingly AI-driven market.
Cyera has been actively consolidating the security market in 2026. The acquisition of Oasis Security marks its third major deal this year, but it is by far the most strategic. Oasis Security specializes in identity and access management solutions designed specifically for the operational realities of AI agents.
“The combination of Cyera’s data security leadership and Oasis’s agent-specific identity protection creates a comprehensive solution for the AI era,” said Yoni Allon, CEO of Cyera.
For Cyera, which started as a dominant force in cloud data security, the addition of Oasis bridges the critical gap between protecting data and controlling who—or what—can access it. The company is effectively creating a new category: AI Agent Security.
Roi Ilany, CEO of Oasis Security, framed the deal in terms of market timing and necessity. “Securing AI agents at scale is one of the most pressing challenges for modern enterprises. This acquisition directly addresses that need.”
The deal underscores a broader industry realization: you cannot secure data without securing identity, and you cannot secure identity in the age of autonomous AI without dedicated, purpose-built agent tools.
What does a robust solution for AI agent security look like in practice? Based on the combined intellectual property and expertise of Cyera and Oasis, we can define a clear and actionable framework for enterprise security leaders.
Every AI agent requires a unique, verifiable, and temporary identity. Oasis provides the critical infrastructure to issue, rotate, and instantly revoke credentials for agents dynamically. This prevents the common problem of long-lived “zombie” credentials and dramatically reduces the blast radius in the event of a compromise.
Agents must be governed by strict, contextual data access policies. Cyera’s DSPM platform continuously discovers and classifies sensitive data across cloud, SaaS, and data center environments. It applies fine-grained access controls so that when a compromised agent attempts to access restricted data, the system can block the action in real time.
A legitimate agent can quickly turn malicious if hijacked. Combining Cyera’s rich data activity monitoring with Oasis’s behavioral identity telemetry creates a powerful baseline for normal agent behavior. Anomalies—such as a customer support agent suddenly attempting to access the finance module—trigger immediate alerts and automated response actions.
As regulatory bodies tighten their scrutiny of AI, the need for a comprehensive audit trail is non-negotiable. The combined platform offers a single pane of glass for understanding exactly which agents are operating, what data they are touching, and whether their actions comply with internal policies and external regulations like the EU AI Act.
Cyera’s massive bet on Oasis is not happening in a vacuum. Investment in AI-focused cybersecurity startups has skyrocketed, rising 180% from 2025 to 2026. Venture capital firms and strategic acquirers are urgently pouring capital into the foundational infrastructure required to safely deploy AI at scale.
The economic logic is simple: if enterprises are going to spend billions of dollars deploying and running AI agents, they must spend a significant percentage securing them. Cyera’s $1 billion acquisition of Oasis Security is a leading indicator of this exact market reality.
Consolidation is the dominant theme here. Enterprise buyers are exhausted by the proliferation of point solutions. They want a unified platform that seamlessly integrates data security, identity management, and posture management. Cyera is actively positioning itself to be the dominant platform in this space.
For CISOs and security architects paying attention, the Cyera-Oasis deal provides a clear and actionable blueprint for the immediate future. The time to prepare for the AI agent wave is now.
With 78% of enterprises expected to have adopted AI agents by 2027, the window for getting ahead of this security challenge is closing rapidly. Multi-billion dollar moves like this one are a clear signal to the market that the infrastructure for secure AI is being built right now.
Cyera’s acquisition of Oasis Security for $1 billion is a watershed moment for enterprise cybersecurity. It directly confronts the most significant security challenge of the AI era: managing and protecting the identities of autonomous agents that handle sensitive data at machine speed.
By combining Cyera’s established data security strength with Oasis’s innovative agent-specific IAM capabilities, the combined entity is creating a comprehensive solution tailored for the realities of modern AI deployments.
The most important takeaway for security leaders is this: The era of the AI agent is already here, and the security models of the past are no longer sufficient. The $1 billion bet from Cyera and Oasis proves that this is the most critical security investment your organization can make in the coming years. Start your audit today.
Non-human identities (NHIs) include API keys, service accounts, OAuth tokens, and AI agents themselves. They are critical because AI agents operate autonomously at machine speed, generating thousands of identity requests per minute, which traditional IAM solutions designed for humans cannot handle effectively.
Traditional IAM assumes a human is behind every credential request, with human-scale interaction patterns and oversight. AI agents, however, run autonomously, interact with multiple APIs, and require continuous monitoring of both identity and data access, making dedicated agent-specific identity protection necessary.
AI agents can generate thousands of identity requests per minute and access sensitive data at machine speed, allowing a compromised agent to exfiltrate large amounts of data before a security team can react. Traditional solutions lack the ability to monitor and govern these non-human identity behaviors and data flows.
Cyera's DSPM provides visibility into data access, usage, and movement, which is essential for understanding how AI agents interact with sensitive data. Oasis Security brings agent-specific identity and access management (IAM), together offering a comprehensive solution that protects both the identity and data aspects of AI agents.
Enterprises should consider the explosion of non-human identities, the need for real-time monitoring and governance of agent behavior, and the integration of data security with identity management. The Cyera-Oasis acquisition highlights the importance of a unified approach to securing AI agents across both identity and data domains.