Cyera Buys Oasis Security for $1 Billion to Rein In AI Agents Before They Run Wild
Two Israeli-founded security firms are merging to solve a problem most companies haven't fully noticed yet: AI agents that grab every permission they're given and never let go.

Key points
- Cyera announced plans to acquire Oasis Security for approximately $1 billion in cash and stock earlier this month.
- Oasis Security specialises in controlling "non-human identities", automated programs, API keys and AI agents rather than human user accounts.
- The deal is part of a broader industry wave: Cisco, CrowdStrike and Palo Alto Networks have each recently bought similar companies.
- Cyera has raised $2 billion in total funding and was valued at $12 billion after a $600 million round in June 2024.
- The two companies share common investors, including Sequoia Capital and Accel, and their founders met during military service in Israel.
When you log into your work laptop, your employer's systems give you access to certain files and nothing more. That boundary is managed by software called identity and access management, or IAM, a system built around the idea that a person with a job title needs specific permissions, is responsible for their actions, and will use only a fraction of what they're allowed to touch.
AI agents don't work that way.
An AI agent is a piece of software that can browse systems, send emails, run searches and take actions automatically, with no human clicking anything. These agents are increasingly common inside businesses, handling tasks from customer queries to financial reporting. The problem, as Oasis Security co-founder and CEO Danny Brickman frames it: traditional access controls were built for humans, and agents are not humans.
"They act differently, they're greedy, they operate differently," Brickman told Dark Reading. "The trust model broke with agents because they're not responsible, they're not accountable, they don't have job titles."
Why does it matter how much access a program has?
Humans typically use about 4 percent of the permissions their employer grants them. According to Cyera chief strategy officer Jason Clark, agents tend to use 100 percent. That gap is dangerous.
If a criminal or a rogue piece of software hijacks an AI agent that has sweeping access, it can read, copy or delete far more data than a hijacked human account ever could. Controlling that "permission envelope", shrinking what an agent is allowed to do to only what it actually needs, is the core problem Cyera and Oasis are trying to solve together.
What will the combined company actually do?
Cyera focuses on finding and classifying sensitive data inside a company's systems. Oasis focuses on managing the accounts used by machines and software rather than people, things like service accounts (login credentials used by one program to talk to another), API keys (digital passcodes that let software connect to external services) and AI agents.
Put together, the argument is that you can't control what an agent accesses unless you understand both the agent's permissions and the sensitivity of the data it can reach. Clark sketched a five-stage approach: discover the data, map the identities, understand what the data contains, check whether an agent's action matches its stated purpose, and intervene in real time if something looks wrong.
"We can stop, right now, immediately, the connection with an identity because we figure out it's accessing data it should not access," Brickman said.
| Company | Employees | Total funding | Valuation |
|---|---|---|---|
| Cyera | 1,500 | $2 billion | $12 billion |
| Oasis Security | 150 | $120 million (Series B, March 2024) | Not disclosed |
| Combined (projected) | 2,000+ | N/A | N/A |
The deal is expected to close this quarter. Longer term, Clark says the plan is to build a unified map of data and identities for risk visualisation and the ability to revoke an agent's permissions mid-session, for example, blocking write access to HR systems if the agent was only supposed to be doing research.
Cyera and Oasis are not alone in chasing this market. Cisco bought Astrix for similar reasons, and CrowdStrike acquired SGNL. The flurry of deals signals that controlling AI agents is fast becoming a standard expectation in corporate security, not an optional extra.
What should ordinary employees or IT teams watch for?
Most staff won't interact with this technology directly, but the underlying risk is real. Any AI tool your organisation uses probably runs on a service account with a set of permissions someone configured and then forgot about. Ask your IT team which AI agents are active, what data they can reach, and whether those permissions have been reviewed recently. Stale, over-permissioned accounts are a favourite target for criminals looking for a quiet way in.



