Cyera’s Oasis Security Buy is All About AI Agent Control

Cyera’s $1 Billion Acquisition of Oasis Security Aims to Revolutionize AI Agent Management

In a major move to tackle the growing problem of non-human identities (NHI) in cybersecurity, Cyera has announced plans to acquire Oasis Security for approximately $1 billion. This deal marks another significant consolidation in the industry, as companies seek to bolster their NHI capabilities and rethink privilege access management (PAM) and identity access management (IAM).

At the heart of this acquisition is the convergence of data security and identity into a single control plane for agents. Currently, organizations have separate systems for managing human identities and non-human entities such as AI agents, service accounts, and API keys. However, with the increasing reliance on automation, this fragmented approach is no longer tenable.

The deal will bring together Cyera’s expertise in data security with Oasis Security’s specialized lifecycle management and security solutions for NHI and AI agents. The combined company aims to redefine privileged access around business context rather than static roles, ensuring that emerging agents don’t have unrestricted access to sensitive information.

Jason Clark, Cyera’s chief strategy officer, emphasizes the importance of this convergence: “Data and identity are two sides of the same coin, and identity is very, very fragmented and very legacy.” He notes that humans typically use only a small percentage of their assigned permissions, whereas AI agents will utilize all available privileges, necessitating a new approach to permission management.

Danny Brickman, co-founder and CEO of Oasis Security, explains why traditional IAM/PAM models are no longer sufficient. “Agents break the trust model on which legacy offerings were built,” he says. “They act differently, they’re greedy, they operate differently. We need to reframed privileged access to fit the agentic era.” Brickman highlights that sensitive information accessible to third-party agents should be considered privileged access, even if it’s not labeled as such in traditional systems.

The combined company will focus on a five-stage model for identity and data management: data discovery, identity data, understanding of data, authorization based on intent versus action, and real-time enforcement with human oversight or audit/forensics. Clark emphasizes the importance of controlling access to actions through identity permissions, enforcing hooks at various layers, including endpoints, gateways, and infrastructure.

As the industry continues to grapple with NHI challenges, this acquisition is a significant step towards addressing the issue. With the combined expertise of Cyera and Oasis Security, organizations will be better equipped to manage their AI agents and prevent unauthorized access to sensitive information.

For businesses looking to strengthen their cybersecurity posture, the key takeaway from this deal is the importance of rethinking traditional IAM/PAM models in light of emerging NHI challenges. As Clark notes, “Identity is the most important control – that’s where you control access to any action.” By converging data security and identity into a single control plane for agents, organizations can better protect themselves against the growing threats posed by non-human entities.


Source: Dark Reading — 2026-08-14