The short version: On July 28, 2026, data-security company Cyera agreed to buy Oasis Security for about $1 billion — roughly $700M in cash with the rest in stock, per reports. Oasis doesn't sell firewalls or antivirus. It governs non-human identities: the API keys, service accounts, OAuth grants, and — increasingly — AI agents that hold credentials and act on their own. At a billion dollars, it's the second-largest cybersecurity deal of the year, behind only Accenture's ~$3.2B move on Dragos. The message for anyone shipping agents is blunt: the logins your agents carry are now a billion-dollar problem, and the market just said so.

What Cyera actually bought#

Cyera made its name in data security posture management — knowing where your sensitive data lives and who can reach it. Oasis, founded in 2022, solves the other half of that sentence: what can reach it. Its platform does non-human identity (NHI) discovery and agentic access management — enumerating every credential that acts without a human in the loop, then attaching each to an owner, a least-privilege scope, and a lifecycle (rotation, decommissioning) (TechCrunch, SecurityWeek).

Put the two together and you get one platform that can answer a single question end to end: who — or what — can touch this data, and should they? That's the deal's logic in one line. It's also Cyera's second acquisition in under a year, which tells you this isn't opportunism; it's a roadmap.

Data security answered "where is the data." Agent identity answers "what is reaching for it." You can't ship autonomous agents and only own the first half.

Why the price is a billion dollars#

The valuation only looks aggressive if you haven't counted the identities. Every AI agent you ship is a non-human identity — to do anything useful it must hold a provider key, a cloud role, a database secret, an MCP server token, and it uses them autonomously. And those identities have already swamped the humans: Palo Alto Networks' 2026 Identity Security Landscape counts 109 machine identities for every human, up from 82:1 a year earlier, with about 79 of the 109 now AI agents; GitGuardian's numbers land near 80:1. We laid out that scale — and why your employee-grade IAM covers none of it — in the non-human identity governance playbook.

This is the second big NHI signal in a month. In mid-July, Oak left stealth with a $60M seed to build an "AI-native identity operating system" (we covered it in agent identity just got a $60M seed), and Cisco absorbed Astrix. A $60M seed prices the category; a $1B acquisition prices the consolidation. When both happen inside four weeks, the market has stopped treating non-human identity as a feature of legacy IAM and started treating it as its own layer.

What a founder should actually do#

You do not need to buy an enterprise platform to respond to this. You need to do the founder-scale version of what Cyera just paid a billion dollars for. Three moves, in order:

The through-line#

For two years the agent conversation was about capability — better models, longer context, more autonomy. The Cyera–Oasis deal marks the point where the governance conversation caught up and got a price tag. Autonomy without identity is just an untracked credential with initiative, and enterprises have now put a billion dollars behind fixing that. You don't have to spend a billion. You do have to spend an afternoon: list your agents' credentials, give each an owner, and put an expiry on every one — before someone else audits it for you.