What is AI agent security, and why did it just become a $1 billion acquisition target

A year ago, the list of "identities" in a company's digital environment was made up largely of human employees and a handful of automated service accounts. Today, that same list may include dozens, even hundreds, of AI agents sending emails, writing code, querying databases, and responding to customer requests on their own. The problem is that most of these agents operate outside the security frameworks designed for human employees.
Traditional corporate security is built around verifying who an employee is, limiting which systems they can access, and monitoring for suspicious behaviour. That model rests on the assumption that a human logs in, works at predictable hours, and displays a recognisable pattern of behaviour. An AI agent, by contrast, can carry out thousands of actions in seconds, activate in the middle of the night, and request access to other systems without human oversight.
That creates an entirely new category of problem for security teams: what happens if an agent's credentials are stolen, or if the agent itself is manipulated through a malicious instruction? Many agents are deployed with permissions broad enough to access sensitive data or take actions without human approval, making them an attractive target for attackers.
The roughly $1 billion deal in which data-security company Cyera has agreed to acquire identity-security startup Oasis Security targets that gap directly. Oasis has built a platform that helps organisations discover, monitor, and manage non-human identities — service accounts, API keys, and an increasing number of AI agents.
The deal marks Cyera's third acquisition this year, signalling a strategy that is rapidly expanding from data security into identity security. Industry observers read this string of acquisitions as a sign that major security companies are racing to make AI agent management a core part of their platforms rather than a separate product category.
One reason the AI agent security market is growing so quickly is that corporate adoption is far outpacing security infrastructure. Companies are rolling out agents rapidly to capture efficiency gains, but the tools to govern those agents' access typically arrive later, often only after an incident has already occurred.
Experts stress that an AI agent's "identity" is fundamentally different from a human one: an agent's behaviour can shift depending on the instructions it was given, the data it accesses, and the other systems it interacts with. That means traditional, static access-control models may fall short for AI agents.
The risk is not merely theoretical: security researchers have documented real-world cases in which misconfigured or over-privileged AI agents were manipulated by attackers to access sensitive data or carry out unauthorised actions. Incidents of that kind have been the main force convincing corporate decision-makers to prioritise the issue.
Analyst firms expect the AI agent security market to grow exponentially over the next several years, drawing in both major security companies and new startups. The Cyera-Oasis deal is one of the largest consolidation moves in the space so far, but it is unlikely to be the last.
The bigger question, according to experts, is whether security standards can keep pace as AI agents become even more widespread across corporate environments. For now, the answer remains unclear — but billion-dollar deals suggest investors, at least, are taking the question seriously.
Read next

What is Kimi K3, and how its architecture differs from other large language models
Kimi K3, developed by the Chinese AI lab Moonshot AI, has drawn attention from researchers for its architectural design choices. An independent analysis examines how the model balances efficiency and scale, and where those choices diverge from the approach taken by Western labs. Here is what Kimi K3 is, and what stands out about its architecture.

Why employees at major AI labs are asking the US government to step in
Employees from companies including OpenAI, Anthropic, Google, Meta, Thinking Machines, Microsoft, and Mistral have signed a joint statement addressed to the US government. The statement warns that the world's leading AI companies may soon be close to systems that can automate AI research itself, and calls for coordinated global governance. Here is what the signatories are worried about, and what they are asking for.

Why AI data centers are straining the largest power grid in the United States
Data centers that train and run AI models are multiplying so quickly that the operator of the largest power grid in the United States is now considering temporarily cutting their power to prevent broader blackouts. Why has demand grown so fast, and how are grid operators responding? Here is what to know.

Is AI actually replacing workers? What Google's own usage data shows
Talk of AI sweeping away entire jobs has dominated the tech industry for two years. A new analysis from Google, examining 15 million real AI interactions, paints a far more measured picture: most tasks in most jobs remain largely untouched so far. Here is what the data actually shows, and where the gap between hype and reality comes from.

Amazon expands its satellite network for mobile phones, turning up the heat on SpaceX
Amazon is expanding its plans to provide direct-to-device satellite connectivity for mobile phones, a move that could challenge SpaceX's Starlink lead in the space. The company has filed with the FCC for a new satellite constellation aimed at providing voice, messaging, data and emergency services. It marks the newest front in a growing space-based rivalry between the two tech giants.