MasterNodeAI
news

Cyera raises $400M from Goldman Sachs for AI agent security push

Cyera adds $400M from Goldman Sachs to its Series G at $12B+ valuation, betting on AI agent security after Oasis Security acquisition.

news

Cyera raises $400M from Goldman Sachs for AI agent security push

What Happened

On September 22, 2026, cybersecurity startup Cyera Ltd. announced it has raised $400 million in funding from Goldman Sachs. The investment bank provided the capital as an extension to Cyera's Series G round, which originally closed in June 2026 at a $12 billion valuation. Cyera now states it is worth "over $12 billion" but did not share an exact updated figure.

The funding extension follows a significant strategic shift for the company. After the June Series G close, Cyera expanded its focus from data security into AI agent security — launching two new products: Agent Guardian, which inventories AI agents interacting with enterprise data, scans them for vulnerabilities (such as overprivileged access), and can block or quarantine agents that violate security policies; and Cyera Endpoint, which monitors AI agents running on employee devices and prevents unauthorized data exfiltration.

Earlier in September 2026, Cyera completed its $1 billion acquisition of Oasis Security Ltd., a startup that secures nonhuman identities (NHIs) — the accounts AI agents use to log into enterprise applications. Oasis can map NHIs across a corporate network, identify which agents use them, and flag risks like overly broad access permissions.

Cyera CEO Yotam Segev said: "AI infrastructure is moving faster than the security architecture around it. This investment accelerates our work to bring data and identity together, so enterprises can give agents access with confidence and keep that access aligned with business intent."

Why It Matters

Cyera's moves — $400M in fresh capital, two new agent security products, and a $1B acquisition — collectively signal that AI agent security is crystallizing as a distinct market category with serious financial backing. This isn't a feature add-on; it's a land grab.

The core problem Cyera is addressing: as enterprises deploy autonomous AI agents that access business systems via nonhuman identities, the traditional security perimeter breaks down. Most existing tools were designed for human users, not for agents that can move data, execute actions, and chain tool calls at machine speed. Cyera is betting that enterprises will need purpose-built tools to inventory agents, enforce access policies, and monitor agent behavior on endpoints.

The Oasis acquisition is particularly strategic. Nonhuman identity management is the authentication layer for agent security — if you can't control what accounts agents use and what permissions those accounts have, you can't secure the agents. By combining data security (Cyera's core) with NHI management (Oasis), Cyera is building an integrated stack that could become a default procurement category for enterprises scaling agent deployments.

For operators, the signal is clear: agent governance and NHI security are moving from "future concern" to "current procurement priority." The capital flowing into this space — Cyera alone has now raised well over $400M in extensions while spending $1B on acquisitions — indicates investors see enterprise demand materializing now, not in 2027.

Who Is Affected

Enterprise security and IT leaders deploying AI agents need to assess whether their existing identity and access management (IAM) tooling covers nonhuman identities. Most doesn't. If agents are accessing enterprise data through service accounts or API keys, those access paths are likely under-monitored.

AI startup founders building agent platforms should expect enterprise buyers to start asking about agent security controls — inventory, policy enforcement, data access auditing — within the next 1-2 quarters. This is becoming a vendor evaluation criterion, not a post-deployment afterthought.

Cybersecurity competitors should note the consolidation velocity. Cyera's $1B Oasis acquisition and $400M extension suggest the window for building a standalone AI agent security startup may be narrowing as well-funded incumbents acquire capabilities and expand their footprints.

Strategic Implications

For AI startup founders: If you're building agent-based products, budget for security compliance now. Enterprise buyers will increasingly require evidence that your agents can be inventoried, policy-controlled, and monitored. Either build these controls into your platform or integrate with a vendor like Cyera early — don't wait for procurement to block your deal.

For developers/operators building with AI APIs: Audit your agents' data access patterns. Tools like Agent Guardian can detect agents with access to more data than they require — a common vulnerability when agents are provisioned with broad permissions for convenience. Implement least-privilege access for agent accounts now, before a security tool flags it for you.

For non-technical business owners evaluating AI tools: When procuring AI agent platforms, ask vendors three questions: How are agent identities managed? Can agents be inventoried and policy-controlled? What happens if an agent violates a data access policy? If the vendor can't answer these clearly, it's a red flag — this is becoming a baseline enterprise requirement.

What to Watch Next

Monitor whether other major cybersecurity incumbents (CrowdStrike, Palo Alto Networks, Zscaler) respond with their own AI agent security products or acquisitions. Also watch for enterprise procurement RFPs that explicitly include agent security and NHI management requirements — that will confirm the category has moved from vendor-push to buyer-pull.

Frequently Asked Questions

Q: What is nonhuman identity (NHI) security and why does it matter for AI agents?

A: Nonhuman identities are the accounts, API keys, and service credentials that AI agents use to access enterprise applications. NHI security involves mapping these identities, monitoring their permissions, and flagging risks like overprivileged access. It matters because most traditional IAM tools were built for human users and don't adequately cover the explosion of agent-driven access paths.

Q: How does Cyera's Agent Guardian work?

A: Agent Guardian inventories AI agents that interact with a company's data, scans them for vulnerabilities (such as access to more data than needed), identifies security issues in agent tools and MCP servers, and can block risky agent actions or quarantine agents that pose broader security risks. Customers define policies for what agents can and cannot do, and Cyera automatically detects non-compliant tools.