ByteBulletin

[funding] · · 2 min read

Cyera Acquires Oasis Security for $1B to Rein In Rogue AI Agents

The data security unicorn bets big on non-human identity management as enterprises struggle to control proliferating AI agents.

By ByteBulletin Editors · Editorial Team

[funding]

Data security company Cyera has signed a letter of intent to acquire Oasis Security for roughly $1 billion, mostly in cash. The deal, announced Tuesday, underscores a fast-growing segment of cybersecurity: managing the deluge of AI agents that enterprises are deploying.

Oasis focuses on non-human identities — think API keys, service accounts, and especially AI agents. As companies rush to automate workflows with agents, each one needs permissions to access data and systems. Without proper oversight, these agents can become vectors for data leaks or privilege escalation. Oasis monitors agent behavior and enforces least-privilege access.

Cyera, fresh off a $600 million round at a $12 billion valuation, has been on an acquisition tear. Earlier this year it snapped up Ryft and Genie Security. Integrating Oasis’s technology will let Cyera offer a unified platform that ties together identity governance and data security — a combination the company hopes will become the control plane for enterprise AI operations.

The acquisition also signals how the cybersecurity market is pivoting. Traditional identity security was built for humans. AI agents behave differently: they scale quickly, make API calls autonomously, and often inherit permissions from the humans who created them. Startups like Oasis, and rivals such as Aponthus and Entro Security, are racing to build purpose-built tools for this new reality.

Cyera says it will absorb Oasis’s team and technology, though the exact integration timeline remains unclear. The combined entity will face entrenched identity players like SailPoint and Okta, which are also adding agent-aware capabilities. But Cyera’s advantage may be its data security foundation — understanding what data an agent can access, not just which systems it can reach.

Why it matters

AI agents are being deployed faster than security teams can keep up. Each agent creates a new identity that can be hijacked or misconfigured. Cyera’s bet is that the market for non-human identity management will explode — and that bundling it with data security gives them a moat against broader identity platforms. For developers, this means more guardrails in the tools they use to spin up agents, but also more complexity in managing permissions across human and machine identities.

SHARE

← All stories