Tech

What is AI agent security, and why did it just become a $1 billion acquisition target

TechCrunch1 h ago
A server room inside a data center
A server room inside a data centerPhoto: Brett Sayles / Pexels

A year ago, the list of "identities" in a company's digital environment was made up largely of human employees and a handful of automated service accounts. Today, that same list may include dozens, even hundreds, of AI agents sending emails, writing code, querying databases, and responding to customer requests on their own. The problem is that most of these agents operate outside the security frameworks designed for human employees.

Traditional corporate security is built around verifying who an employee is, limiting which systems they can access, and monitoring for suspicious behaviour. That model rests on the assumption that a human logs in, works at predictable hours, and displays a recognisable pattern of behaviour. An AI agent, by contrast, can carry out thousands of actions in seconds, activate in the middle of the night, and request access to other systems without human oversight.

That creates an entirely new category of problem for security teams: what happens if an agent's credentials are stolen, or if the agent itself is manipulated through a malicious instruction? Many agents are deployed with permissions broad enough to access sensitive data or take actions without human approval, making them an attractive target for attackers.

The roughly $1 billion deal in which data-security company Cyera has agreed to acquire identity-security startup Oasis Security targets that gap directly. Oasis has built a platform that helps organisations discover, monitor, and manage non-human identities — service accounts, API keys, and an increasing number of AI agents.

The deal marks Cyera's third acquisition this year, signalling a strategy that is rapidly expanding from data security into identity security. Industry observers read this string of acquisitions as a sign that major security companies are racing to make AI agent management a core part of their platforms rather than a separate product category.

One reason the AI agent security market is growing so quickly is that corporate adoption is far outpacing security infrastructure. Companies are rolling out agents rapidly to capture efficiency gains, but the tools to govern those agents' access typically arrive later, often only after an incident has already occurred.

Experts stress that an AI agent's "identity" is fundamentally different from a human one: an agent's behaviour can shift depending on the instructions it was given, the data it accesses, and the other systems it interacts with. That means traditional, static access-control models may fall short for AI agents.

The risk is not merely theoretical: security researchers have documented real-world cases in which misconfigured or over-privileged AI agents were manipulated by attackers to access sensitive data or carry out unauthorised actions. Incidents of that kind have been the main force convincing corporate decision-makers to prioritise the issue.

Analyst firms expect the AI agent security market to grow exponentially over the next several years, drawing in both major security companies and new startups. The Cyera-Oasis deal is one of the largest consolidation moves in the space so far, but it is unlikely to be the last.

The bigger question, according to experts, is whether security standards can keep pace as AI agents become even more widespread across corporate environments. For now, the answer remains unclear — but billion-dollar deals suggest investors, at least, are taking the question seriously.

This article is an AI-curated summary based on TechCrunch. The illustration is a stock photo by Brett Sayles from Pexels.

Read next

The exterior facade of a government building
Tech

Why employees at major AI labs are asking the US government to step in

Employees from companies including OpenAI, Anthropic, Google, Meta, Thinking Machines, Microsoft, and Mistral have signed a joint statement addressed to the US government. The statement warns that the world's leading AI companies may soon be close to systems that can automate AI research itself, and calls for coordinated global governance. Here is what the signatories are worried about, and what they are asking for.

The Verge1 h ago