- 45 non-human identities (NHIs) per human employee on average, skyrocketing to 144-to-1 in cloud environments.
- 500% growth in NHIs in Fortune 500 companies over the last six months.
- $12 billion valuation for Cyera after acquiring Oasis Security for $1 billion.
Experts would likely conclude that Cyera's acquisition marks a critical step in addressing the escalating challenge of securing AI-driven autonomous systems, though it also raises concerns about centralizing control in a single governance platform.
The Ghost in the Machine: Cyera's $1B Bet to Tame AI's Unseen Workforce
NEW YORK, NY – September 03, 2026 – In a move that signals a seismic shift in how we control our own digital creations, cybersecurity firm Cyera has finalized its $1 billion acquisition of Oasis Security. The deal unites a leader in AI data security with a specialist in managing the credentials of non-human 'agents.' On the surface, it’s a landmark transaction in a booming industry. Beneath the press releases and soaring valuations, however, it’s an admission of a terrifying new reality: we are rapidly losing track of the invisible, autonomous workforce we’ve unleashed within our most critical systems.
The Billion-Dollar Problem You Didn't Know You Had
For decades, enterprise security was built on a simple, flawed assumption: a human was at the keyboard. You could train, monitor, and, if necessary, discipline a person. But the landscape has changed. The fastest-growing population inside the world's largest companies isn't human. It’s a ghost army of non-human identities (NHIs)—API keys, service accounts, and AI agents—that now outnumber their human counterparts by staggering ratios. Recent research reveals there are, on average, 45 non-human identities for every one human employee in a typical enterprise, a figure that skyrockets to 144-to-1 in modern cloud environments.
The press release from Cyera notes that these identities have grown nearly 500% in Fortune 500 companies in just the last six months. This isn't just growth; it's a Cambrian explosion of code that acts on our behalf. Unlike a human employee who might use only 10% of their access permissions, an AI agent, by its very nature, will seek to use 100% of what it's given. It operates at machine speed, 24/7, with no need for phishing or hacking. It acts on valid credentials. The problem is no longer just about preventing break-ins; it's about controlling the authorized occupants who have no conscience, no fear of reprisal, and a mandate to act.
“You can't threaten an agent, prosecute an API, or discipline a workload,” the company’s announcement starkly admits. This is the billion-dollar problem. The old model of trust, based on static permissions and human accountability, is not just obsolete; it's a catastrophic liability. A permission granted six months ago to an autonomous system is a ticking time bomb, a forgotten key to a kingdom the gatekeeper no longer recognizes.
A New Arms Race in AI Security
The Cyera-Oasis deal isn't happening in a vacuum. It's the latest high-profile maneuver in a frantic arms race among cybersecurity titans to become the definitive control plane for enterprise AI. With this acquisition, Cyera, now valued at a colossal $12 billion after raising over $2.3 billion, is making a bold play to outflank its rivals. Competitors like Cisco, CrowdStrike, and Palo Alto Networks have all made multi-billion dollar acquisitions in the identity space, desperately trying to bolt on solutions for this new threat.
Cyera’s strategy is to build a unified system from the ground up. “The speed of this deal reflects a shared conviction that AI has changed the game, and the infrastructure to secure it has to move just as fast,” said Yotam Segev, Cyera’s cofounder and CEO. This isn't just about patching a hole; it's about architecting a new type of digital governance. Investors are rewarding this vision with staggering sums, betting that the company that secures enterprise AI will hold a position of unparalleled power and influence.
By integrating Oasis’s platform—which will now be known as Cyera Identity—Cyera aims to create a single system that answers a profoundly complex question in real-time: what should this specific agent, at this exact moment, be allowed to see and do? It’s a shift from a perimeter-based defense to a dynamic, context-aware model of perpetual verification.
Unifying Data and Identity: The Technical Gambit
The promise is a single source of truth. Cyera built its name by giving companies a god-level view of their data—where it is, who touches it, and whether it’s at risk. Oasis built a platform to manage the exploding population of agents touching that data. “Put those two things together and you get one system that decides what every agent can see and do, and that's exactly what we’re building,” Segev explained.
In practice, this means moving away from the brittle model of static, standing permissions. The new paradigm, as articulated by the combined company, is to evaluate trust fresh before every single action. When an AI agent attempts to access a dataset, the system won’t just check if it has a key; it will ask if it should have the key, right now, for this specific purpose, based on a complex web of policies and real-time context. It’s an attempt to embed a form of digital judgment into the very fabric of the network.
“Cyera shares that same goal and together, we're positioned to deliver a single platform that governs identity and data as one,” added Danny Brickman, the cofounder and CEO of Oasis. For customers, he argues, this is a win for anyone “forced to stitch those two things together until now.” The goal is to provide the 'trust layer' that allows companies like Chipotle and Paramount to unleash AI on their most sensitive systems without fear of an autonomous blunder.
The Unseen Cost of the Agentic Enterprise
Yet, as we rush to build these powerful new systems of control, we must pause and ask who, ultimately, is in control. In the quest to solve the problem of unaccountable AI, we are consolidating immense power into a new form of technical authority. A single platform that “governs identity and data as one” and decides “what every agent can see and do” is not just a security tool; it is a new form of corporate infrastructure, as fundamental as the power grid or the internet itself.
What happens when this trust layer fails? Or when its policies, written by humans, have unintended consequences that are executed at machine speed across an entire organization? The very centralization that provides security also creates a single, catastrophic point of failure. We are trading an army of unaccountable agents for a single, all-powerful governor. The gap between how this world should work and how it does is filled with complexity, and a purely technical solution, no matter how sophisticated, often ignores the human element that designed it. The agentic enterprise may be more secure, but it will also be more opaque, its actions dictated by algorithms we are told we must trust.
Topics & Related
Agentic AI
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →