Cyera to Buy Oasis Security for $1B to Cover AI Agent Identity Risk
Cyera signed a letter of intent to acquire Oasis Security for ~$1B in mostly cash. Oasis specialises in non-human identity security for AI agents.
Data security firm Cyera announced on Tuesday, July 28, 2026, that it has signed a letter of intent to acquire Oasis Security for roughly $1 billion. The deal will be paid mostly in cash, with the remainder in Cyera shares. Oasis, founded in 2022, specialises in securing non-human identities, meaning AI agents and the permissions they hold to access other software. The acquisition signals how quickly the market for AI-focused cybersecurity is moving, and how seriously enterprises now treat the risk of unmanaged agents acting inside their systems.
What happened
| Detail | Figure |
|---|---|
| Deal price | ~$1 billion (mostly cash) |
| Cyera valuation (last round) | $12 billion |
| Cyera last funding round | $600 million |
| Cyera total funding raised | ~$2.3 billion |
| Cyera annual recurring revenue | $150 million+ |
| Oasis total funding raised | ~$195 million |
| Oasis founded | 2022 |
Cyera, a data security company that has been operating for five years, announced the letter of intent on July 28. The remainder of the purchase price not paid in cash will be settled in Cyera stock. Oasis’s backers include Accel, Craft Ventures, and Cyberstarts. Notably, Accel and Cyberstarts also back Cyera, so both companies share investors.
This is not Cyera’s first acquisition recently. The company also bought Ryft, which was backed by Index Ventures, and Genie Security, a firm that was less than one year old at the time of purchase.
Why does non-human identity security matter now?
Non-human identity security covers software entities, primarily AI agents, rather than human employees. As businesses deploy more autonomous AI agents to handle tasks across their software stack, each agent needs credentials and permissions to operate. Without proper oversight, those agents can become a blind spot: they accumulate access rights, behave in unexpected ways, and can be exploited if compromised.
Oasis builds tooling that monitors agent behaviour and controls what each agent is permitted to access. That capability plugs a gap that traditional identity and access management (IAM) tools were not designed to cover, because most IAM products were built for human users logging into systems, not for automated agents running continuously in the background.
After the deal closes, Cyera plans to fold Oasis’s technology into a combined identity and data security platform. The pitch to enterprise buyers would be a single product that sees both what data exists and who, or what, is touching it.
The wider market context
The acquisition fits a broader pattern in cybersecurity. As AI tools become standard inside enterprise workflows, the attack surface grows. Agents can be weaponised, misconfigured, or simply over-permissioned. Security vendors are racing to build coverage before the risks become widespread incidents. Microsoft, for example, recently launched its first dedicated cybersecurity AI model alongside a new agentic security system.
For Cyera specifically, the deal accelerates a strategy of assembling a broad security platform through acquisitions rather than purely organic development. The company has the capital to do it: $2.3 billion raised in total.
The one caveat worth noting: Cyera has cleared $150 million in ARR but is not yet profitable, per TechCrunch’s reporting from last month. A $1 billion acquisition while still in the red is a meaningful bet on continued growth in enterprise AI security spending.
Our take
The price tag is large for a four-year-old company, but the logic is sound. Any business running AI agents in production right now is almost certainly under-invested in monitoring what those agents can access and do. Most IAM setups were not built for this. Oasis addresses a real and specific problem, which is why it attracted $195 million before being acquired.
If you are a business evaluating AI integration for your operations, the identity and permissions question is one you should be asking before deployment, not after an incident. The fact that a $12 billion company just spent $1 billion to fill this gap tells you something about how seriously the industry treats it.
We have been tracking the wave of AI security acquisitions on the Lumien news desk. This one stands out because it is not about defending against AI-generated phishing or deepfakes. It is about the agents you are choosing to run inside your own systems. That is a closer and more immediate risk for most businesses.
What to do about it
- Audit every AI agent or automation currently running in your business and list what software access each one holds.
- Apply the principle of least privilege: each agent should have only the permissions it strictly needs to complete its task.
- Set up logging so you can see what each agent does, when, and on whose behalf.
- Revisit your IAM provider and ask specifically whether their tooling covers non-human identities and service accounts, not just human users.
Managing agent permissions is fast becoming a baseline security requirement, not an advanced concern.
Frequently asked questions
How much is Cyera paying for Oasis Security?
Cyera agreed to acquire Oasis Security for approximately $1 billion, with the deal paid mostly in cash and the remainder in Cyera shares.
What does Oasis Security do?
Oasis Security focuses on securing non-human identities, primarily AI agents. It builds software that monitors agent behaviour and manages the permissions agents hold to access other software.
How much has Cyera raised in total?
Cyera has raised approximately $2.3 billion in total funding, including a $600 million round that valued the company at $12 billion.
Is Cyera profitable?
No. According to TechCrunch reporting from last month, Cyera has surpassed $150 million in annual recurring revenue but is not yet profitable.