AI Access Control

Oasis Security Signs LOI to Be Acquired by Cyera to Build Next-Generation AI Security Platform

Oasis Security has signed a letter of intent to be acquired by Cyera as the two companies move to build a next-generation AI security platform. The partnership combines Oasis’s expertise in non-human identity and agentic access governance with Cyera’s data security capabilities. The goal is to give enterprises unified control over which AI agents can access what data, in what context, and under which policies — addressing the rising risks of autonomous agents operating in production environments.

Updated on July 28, 2026
Oasis Security Signs LOI to Be Acquired by Cyera to Build Next-Generation AI Security Platform

Oasis Security announced today that it has signed a letter of intent to be acquired by Cyera, with the transaction now in the process of completion. The two companies plan to jointly build a next-generation security platform designed to help enterprises put AI agents to work in their most important systems while maintaining control.

The announcement comes as AI agents move from pilots into production faster than traditional identity models were built to handle. These agents reason, decide, and act across core business systems, creating a new class of risk: an agent with valid credentials and the right objective can expose sensitive data or disrupt operations without any external attacker. Oasis and Cyera argue that AI adoption ultimately runs through two control points — access and data — and that both must be governed together.

“AI agents have moved from pilots into production faster than any identity model was built to handle. They reason, decide, and act across the systems that run the business. That creates a new kind of risk: an agent with valid credentials and the right objective can expose sensitive data or disrupt operations with a single wrong decision. No attacker required.”

Danny Brickman, Co-founder and CEO of Oasis Security

Oasis was founded in 2022 with a focus on non-human identity security. The company has spent the past three years helping large enterprises move from static, standing permissions to continuous, policy-driven control over workloads and agents. By joining Cyera, which has redefined data security, the combined entity aims to deliver a platform that sees the full picture: the identity behind every agent, the access it requests, the data it reaches, and the business context that determines the true risk.

For existing Oasis customers, the company states that the platform and team remain focused on non-human identity and agentic access, with the roadmap continuing and accelerating under the new structure.

Conditions Driving the Change

  • AI agents are rapidly moving from experimental pilots into production environments, operating with greater autonomy and interacting with core business systems at a pace that traditional identity models were never designed to support.

  • The number of AI agents inside large enterprises is expected to explode, with Gartner predicting that the average Fortune 500 company will have over 150,000 agents in use by 2028, up from fewer than 15 in 2025.

  • An agent with valid credentials can expose sensitive data or disrupt operations through a single incorrect decision, creating a new class of risk that does not require an external attacker.

  • Traditional identity security models were built for human users and static, long-lived permissions, making them poorly suited for agents that appear in seconds, act independently, and disappear within hours.

  • Non-human identity has become a board-level priority as organizations recognize that access control is now one of the most critical and least mature control points for safe AI adoption.

  • Effective governance of AI agents requires simultaneous control over both access decisions and data context, because knowing who or what can reach which data, when, and under which policy is essential for managing risk.

  • Organizations need continuous, policy-driven control rather than static permissions so they can grant agents the minimum necessary access for the shortest possible time and in the correct business context.

  • The market is consolidating around platforms that can unify identity, access, and data security into a single view, enabling enterprises to scale AI agents while maintaining visibility and control over every action.

What AI Security Looked Like Before

Before the move toward unified platforms that combine non-human identity with data context, AI security for autonomous agents was largely fragmented and incomplete. Organizations typically managed agent access using traditional identity and access management tools designed for human users and static permissions. These systems struggled with the speed and ephemerality of AI agents, which can spin up in seconds, request broad privileges, act independently, and then disappear. Visibility into what agents could actually reach was limited, and security teams often lacked real-time understanding of the data sensitivity or business processes behind each access request.

Governance was usually handled through separate identity and data security stacks that did not talk to each other effectively. This created blind spots: an agent might receive valid credentials while the data it accessed carried high risk that was never factored into the access decision. Standing permissions remained common, leaving agents with longer-lived access than necessary. Audit trails were incomplete or scattered, making it difficult to answer basic questions about which agent acted, what it reached, and whether the action was appropriate. As a result, many enterprises slowed AI agent adoption or limited it to low-risk use cases because they could not confidently control the combination of identity, access, and data risk in production environments.

What AI Security Looks Like Now

With the announced combination of Oasis Security and Cyera, AI security is moving toward a unified platform that treats access and data as two inseparable control points. The joint vision centers on seeing the full picture for every agent action: the identity behind the agent, the access it requests, the data it can reach, and the business context that determines the true stakes. Access decisions can be continuous and policy-driven rather than static, allowing organizations to grant agents only the privileges they need, for the duration they need them, in the correct context.

The platform aims to enable enterprises to put AI agents into their most important systems while maintaining control. By bringing non-human identity governance together with data security context, security teams gain the ability to weigh every access request against both who is asking and what is at risk. This reduces the chance that a well-credentialed but poorly contextualized agent can expose sensitive information or disrupt operations. For customers, the Oasis platform continues with an accelerated roadmap, while the combined capability is expected to deliver richer business context to every access decision. The result is a more complete model for governing the agents that are increasingly running core business processes.

Our Take

AI Security Take

The announced combination of Oasis Security and Cyera marks a significant step in the evolution of enterprise AI security. As AI agents move rapidly into production and begin acting with greater autonomy across core business systems, the traditional separation between identity security and data security is no longer sufficient. The partnership aims to close that gap by building a platform that unifies non-human identity, continuous access control, and data context into a single decision layer.

The core insight is straightforward: every AI agent action ultimately comes down to access. An agent with valid credentials and the wrong objective can expose sensitive data or disrupt operations without any external attacker. By bringing Oasis’s continuous, policy-driven control over non-human identities together with Cyera’s data security capabilities, the combined platform is designed to answer the critical questions in real time — which agent is acting, what it can reach, what it can do, and what the business cost would be if it goes wrong.

This development reflects a broader market shift toward treating agentic AI as a first-class security domain that requires purpose-built controls rather than extensions of human-centric identity models. Organizations that continue to manage agent access with static permissions and disconnected data tools will face growing risk as the number of agents scales. Those that adopt unified platforms capable of governing both access and data context will be better positioned to deploy AI agents into critical systems with confidence.

For security leaders, the practical implication is clear. Safe AI enablement now depends on continuous, contextual control over non-human identities and the data they touch. The Oasis–Cyera combination is one of the clearest signals yet that the industry is consolidating around this model. Enterprises that prioritize integrated identity-and-data governance for AI agents will reduce risk while accelerating the responsible use of autonomous systems across the business.

Related Articles

ServiceNow Launches Autonomous Workforce and Integrates Moveworks Into Its AI Platform AI Governance Platforms

Feb 27, 2026

ServiceNow Launches Autonomous Workforce and Integrates Moveworks Into Its AI Platform

Read More
Arize vs Fiddler vs Arthur: Which AI Monitoring Platform Actually Fits Your Enterprise? Model Observability

Mar 1, 2026

Arize vs Fiddler vs Arthur: Which AI Monitoring Platform Actually Fits Your Enterprise?

Read More
ServiceNow Introduces the Enterprise Identity Control Plane Following Its Acquisition of Veza AI Access Control

Mar 2, 2026

ServiceNow Introduces the Enterprise Identity Control Plane Following Its Acquisition of Veza

Read More

Stay ahead of Industry Trends with our Newsletter

Get expert insights, regulatory updates, and best practices delivered to your inbox