The biggest AI agent security deal to date just happened, and most business leaders have not heard about either company involved. That is about to change.
Data security unicorn Cyera signed a letter of intent to acquire Oasis Security for $1 billion, with roughly $700 million in cash and the remainder in Cyera shares. Cyera was valued at $12 billion after a $600 million funding round in June 2026. Oasis, which was founded in 2022 and raised $195 million total including a $120 million Series B in March 2026, specialises in securing non-human identities: service accounts, API keys, machine credentials, and AI agents.
The combined platform will be able to show what sensitive data an organisation holds and map exactly which humans, machines, and AI agents can access it. That is a capability the enterprise market has been missing.
The Problem This Solves
Most security frameworks were built for a world where only humans had credentials. A person logged in, did something, logged out. The logs tracked the person. Identity governance meant managing human access.
AI agents broke that model.
When a business deploys AI agents, those agents need permissions. They need to read from databases, write to systems, call APIs, and interact with tools. Each of those interactions requires some kind of access credential. And unlike a human employee, an AI agent can act thousands of times per hour, on many tasks simultaneously, touching sensitive data at a pace no human reviewer can keep up with.
The result is that most businesses deploying AI agents today have a blind spot: they do not have clear visibility into what their agents can access, when they accessed it, or whether that access was appropriate. Security teams that are used to governing human access have not yet built the tooling and processes for governing agent access.
That blind spot is exactly what Oasis was built to address. The company maps non-human identities across an organisation’s environment and flags over-privileged agents, orphaned credentials, and anomalous access patterns. Cyera’s data security platform does the same for sensitive data itself.
Together, they cover the full picture: what data exists, how sensitive it is, and which agents (and humans) can reach it.
Why This Matters Now
A $1 billion acquisition does not happen because a problem is theoretical. It happens because the problem is real, growing, and expensive.
Organisations are deploying AI agents faster than their security teams can track them. The number of non-human identities in enterprise environments is now estimated to outnumber human identities by a significant margin, and that ratio is growing as agent deployments scale.
The risk is not primarily that agents behave maliciously. It is that they behave as designed but with access they were never explicitly authorised to have, because nobody mapped what they could reach before deploying them.
A billing agent that has read access to the entire customer database because nobody scoped its permissions correctly. An internal knowledge agent that can surface confidential HR records because it inherited broad search permissions. A sales automation agent that can modify pricing data because its API key was copied from a developer environment that had write access.
None of these are exotic edge cases. They are the predictable consequences of moving fast on agent deployments without a governance framework built for agents.
What This Means for Businesses Deploying AI Agents
The Cyera-Oasis deal is a signal, not a solution to buy immediately. But it tells you something important: the market has decided that AI agent security is a serious enterprise product category, not a niche concern.
If your organisation is deploying AI agents at any meaningful scale, there are three practical questions worth asking now, regardless of what tools you use:
First, do you have a complete inventory of what your agents can access? Not what you intended them to access, but what they actually can access based on the credentials and permissions they were given?
Second, do your audit logs capture agent actions in enough detail to investigate an incident after the fact?
Third, is anyone on your team responsible for reviewing agent permissions the way someone is responsible for reviewing human access during onboarding and offboarding?
If the answer to any of those is “no” or “I’m not sure,” the Cyera-Oasis news is a useful prompt to add them to your roadmap before they become a compliance or breach issue.
The EDNA Take
At Enterprise DNA, every AI agent deployment we build for clients through Omni Ops includes explicit conversations about access scoping and permission governance from the start. Not because we are pessimistic about agents, but because the businesses that benefit most from AI agents are the ones that build with clear guardrails rather than retrofitting them later.
The governance conversation is easier to have before deployment than after. The Cyera-Oasis deal suggests the rest of the market is starting to agree.
If you are planning an AI agent deployment and want to include governance in the design from day one, book a session with Sam to talk through how to structure it.
Source
TechCrunch
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible