Cyera’s proposed acquisition of Oasis Security for $1 billion signals how quickly non-human identity has moved from a specialist concern to a strategic security category. The deal places AI-agent protection alongside data security and cloud security, highlighting the need to understand which software actors can reach sensitive systems and information.

The problem

AI agents create a new identity problem because they combine automation with delegated decision-making. An agent may inherit permissions from a user, use service credentials or obtain access through a workflow. If those relationships are not visible, organisations can struggle to answer basic questions about ownership, authorisation and accountability after an incident.

What security teams should prioritise

A combined platform strategy could connect data context with identity context. Knowing that an agent accessed a sensitive dataset is more useful when security teams can also see the credential used, the policy that allowed the action, the agent’s instructions and the human or business process responsible for it. This is the foundation of meaningful NHI security.

The acquisition also reflects the importance of discovery. Agent identities can be created outside formal IAM processes, particularly when developers assemble tools, plugins and automation in cloud environments. Continuous inventory and relationship mapping can expose dormant accounts, duplicated permissions and agents operating without clear owners.

For buyers, the key test is whether a product can enforce controls at runtime rather than simply produce another inventory. Short-lived credentials, approval gates for sensitive actions, behavioural detection and explainable audit trails should work across cloud and application boundaries. Agentic Identity governance will be strongest when it joins data access decisions to identity lifecycle controls.