Skip to content
By AI Agent Security

Every Identity Giant Just Bought an AI Agent Company. Here's What They Know That You Don't.

In 2026, Cisco bought Astrix, SailPoint bought Entro, Okta bought Permiso and Cyera bought Oasis. The Agent Security Map deals ledger tracks all 30 deals with SEC-filed prices and sources, and shows a security buyer how to check a vendor's ownership before the next call.

Every Identity Giant Just Bought an AI Agent Company. Here's What They Know That You Don't., by Deepak Gupta on guptadeepak.com

Between April 2025 and August 2026, the large identity and security platforms bought the startups that secure AI agents and the non-human identities they run on. Cisco bought Astrix, SailPoint bought Entro, Okta bought Permiso, Cyera bought Oasis, and Palo Alto Networks closed its $21.1 billion purchase of CyberArk. The Agent Security Map's deals ledger records 30 acquisitions since 2024, and 14 of them were announced in 2026 alone.

For a security buyer, the lesson is practical. The vendor you shortlist this quarter has a real chance of belonging to someone else before your contract ends. This post explains what happened, what it means for your roadmap and your contracts, and how to check a vendor's ownership in a few minutes before the call.

Verified as of 25 September 2026 against the sources linked inline.

What is happening: the big platforms bought agent identity

An AI agent is software that takes actions on its own, such as calling an API, reading a file or sending a message. To do that, it needs credentials. Those credentials make it a non-human identity (NHI): an account, token or key used by software rather than a person. Securing those identities was a hot startup category in 2024. By the autumn of 2026, most of its best-known names had been bought.

Four NHI specialists sold in four months

Cisco announced its intent to acquire Astrix Security on 4 May 2026, and said it would fold Astrix into Cisco Identity Intelligence, Secure Access and Duo, per Cisco's announcement. The deal closed on 29 June. Cisco did not disclose terms, and Calcalist reported a price of about $400 million.

SailPoint closed its purchase of Entro Security on the same day, 29 June 2026. Chief executive Mark McClain described the goal as a "unified control plane to govern, secure, and manage the lifecycle of every single identity, human, machine, or AI agent," in SailPoint's closing release. SailPoint's 10-Q puts the purchase consideration at about $122.6 million in cash.

Cyera announced its deal for Oasis Security on 28 July and closed it on 3 September. Its completion release says the acquisition was "valued at $1 billion." Oasis now operates as Cyera Identity. Two days after the Oasis announcement, Okta announced it would acquire Permiso Security, adding detection across human, non-human and agentic identities. That deal closed on 26 August with no disclosed terms.

The biggest deal came first

The largest transaction in the ledger is Palo Alto Networks and CyberArk, the privileged access and machine identity company. Palo Alto's 10-K for the year ended 31 July 2026 reports total purchase consideration of $21.1 billion. CyberArk shareholders received $45.00 in cash plus 2.2005 Palo Alto shares per share, and the deal closed on 11 February 2026.

The same 10-K records Koi, an agent and extension inventory tool, at $231 million and Portkey, an AI gateway, at $117 million. Palo Alto had already bought Protect AI for $634.5 million, per its fiscal 2025 10-K. With four deals, it is the most active buyer in the ledger. Okta, Cyera, Cisco and CrowdStrike made two each.

Why it matters to you as a security buyer

The identity market has run this play before. I founded LoginRadius in 2013 and scaled it past a billion identities. Over that decade, capabilities such as multi-factor authentication started as separate purchases and ended as features inside identity platforms. Agent identity is following the same path, only in about two years instead of ten.

The first consequence is that you may already own agent identity features. SailPoint, Okta, Cisco and Palo Alto now sell NHI and agent capabilities inside platforms you might license today. Before you buy a standalone tool, ask your current identity vendor what it already ships. Otherwise, you may pay twice for agent discovery.

The second consequence is roadmap risk. A startup's roadmap follows its customers. An acquired product's roadmap follows the parent's platform strategy. Integrations with a rival's identity provider or SIEM tend to lose priority, while integrations with the parent's own products move up. None of that shows in your contract unless you write it in before signing.

The third consequence is renaming and repricing. Portkey's gateway now ships as Prisma AIRS AI Gateway, Koi as Cortex Agentic Endpoint Security, and CalypsoAI as F5 AI Guardrails. A rename is harmless on its own. It often comes with a new bundle at renewal, and that is where standalone pricing tends to disappear.

The problem these companies solve has not gone away. Cyera's release claims non-human identities "grew nearly 500% in the last six months." What has changed is where you buy the fix. For most organisations, NHI and agent identity will now arrive through the identity governance, privileged access or data security vendor they already use.

What the Agent Security Map's deals ledger shows

The Agent Security Map is a free, identity-first directory of 61 AI agent security vendors across 12 categories. Its deals ledger lists every acquisition in agent security and agent identity since 2024. Each row carries the announcement date, the close date, the price where one is disclosed, and a link to the source document.

How the ledger is built

Every deal links to the strongest primary document available. That is the acquirer's SEC filing (a 10-K, 10-Q or 20-F) where it states the price, and the acquirer's own release otherwise. A price that only a news outlet reported is labelled "reported" and cites the article. Private-market databases are not used, per the map's methodology page.

Ranges are never recorded as prices. Calcalist estimated $300 to $350 million for Cato Networks and Aim Security, and the ledger lists that deal as undisclosed. Freshness is enforced by the build itself. An acquisition that has not closed must be re-verified within 45 days, or the site refuses to publish.

Ownership also flows into the vendor pages. When a vendor is bought, its record shows the acquirer, both dates and the price basis. The Astrix Security record, for example, reads "Acquired by Cisco, announced 2026-05-04, closed 2026-06-29 ($400M, reported)." Every change is dated on the changelog.

Finding 1: the real price is in the filing

Of the 30 deals, 18 carry a price from an SEC filing, 4 carry a reported price, and 8 have no disclosed price. Filings are the most reliable number because they split cash paid from replacement equity and from stock that vests later as compensation. That split is often missing from the headline figure quoted on announcement day.

DealPrice in the SEC filing
SailPoint and EntroAbout $122.6M cash (10-Q)
CrowdStrike and SGNL$627.9M net cash plus $9.2M replacement awards (10-Q)
SentinelOne and Prompt Security$160.2M total consideration (10-K)
Tenable and Apex Security$47.8M (10-K)
Google and Wiz$29.5B after adjustments, excluding post-combination compensation (Alphabet 10-Q)

Filed prices matter in a negotiation. They show what a buyer actually paid for these capabilities, which is a better anchor than headline figures when a vendor defends its list price.

Finding 2: the agent identity category is now mostly owned

The agent identity and credentials category shows the result most clearly. Five of its vendors now carry an "Acquired by" label: Oasis (Cyera), Permiso (Okta), Astrix (Cisco), Entro (SailPoint) and Natoma (Snowflake). The top two by signal score are SailPoint and Microsoft, both large platforms. Across the whole map, 22 of the 61 vendors have been acquired, and a 23rd, Promptfoo, is being acquired by OpenAI.

Independents remain in the category, including Teleport, Aembit, Keycard and Token Security. Their pitch rests on neutrality across identity providers. That pitch holds only as long as they stay independent, which is exactly what the ledger lets you watch.

Finding 3: open source can go quiet after a deal

Protect AI's LLM Guard, a Python toolkit for scanning prompts and model outputs, is now archived on GitHub. The protectai/llm-guard repository is read-only, with its last push on 8 July 2026 and more than 3,200 stars. Palo Alto Networks closed the Protect AI deal on 22 July 2025, so the project ran for about a year under its new owner.

The map's open-source tracker flags archived and stalled repositories for this reason. Anyone who built guardrails on LLM Guard now maintains a fork, whether they planned to or not.

How to use the deals ledger before a vendor call

Run this check for each vendor on your shortlist.

  1. Search the ledger for the vendor and its parent. Open the deals ledger and look for the vendor as a target. Then look for its likely buyers as acquirers, since a platform that just bought a competitor may cool on the partnership you rely on.
  2. Read the price basis, not just the price. "SEC" means a filing states it. "Reported" means only the press did. "Undisclosed" means neither, so treat any figure you hear on the call as marketing.
  3. Open the source document. Each row links to its filing or release. The acquirer's release often names the product line the target is joining, which tells you where its roadmap now points.
  4. Open the vendor page. Check the "Acquired by" line, the new product name, and the "Last verified" date. The vendor page also lists which identity primitives the vendor claims in its own documentation.
  5. Check open-source health. If you depend on a vendor's library, look it up on the open-source tracker. An archived or stalled repo after a deal is a signal to plan a fork or a replacement.
  6. Bring the consolidation question to the call. Question 11 of the Agent Security Map CISO checklist asks whether the vendor is independent or recently acquired, and what happened to its roadmap and open source after the deal. Ask it directly.

A scorecard helps with the rest of the evaluation, but it has a blind spot here. The CISO Desk POC scorecard says plainly that whether the vendor gets acquired is not scoreable, and yet it decides outcomes after signature. The ledger is how you put a date and a source on that risk.

What to do next

More than a third of the vendors on the map have already been bought. Assume any independent agent security vendor could change hands during your contract, and negotiate for it.

  • Map your current vendors. Check every agent security and NHI tool you run against the deals ledger. For any that were acquired, ask the new owner in writing for the roadmap and end-of-life policy.
  • Ask your identity provider what it already ships. SailPoint, Okta, Cisco, Microsoft and Palo Alto all sell agent identity features now.
  • Add a change-of-control clause. Secure the right to terminate without penalty, or with a pro-rated refund, if the vendor is acquired.
  • Cap renewal pricing. Hold the price for at least one term after a change of control, since acquirers often move standalone products into bundles.
  • Get integrations in writing. List the third-party identity providers, SIEMs and gateways you rely on, and have the vendor commit to keeping them for the contract term.
  • Audit open-source dependencies. Search your code for vendor-owned security libraries such as LLM Guard, and decide whether to fork, replace or buy the commercial successor.

Consolidation also changes pricing power across the market. I made that case in my post on Google's Wiz bet and buyer negotiating power, and the agent identity deals follow the same pattern.

Frequently Asked Questions

Which companies have acquired AI agent security startups?

The Agent Security Map records 30 acquisitions since 2024. Palo Alto Networks made four (CyberArk, Protect AI, Koi and Portkey). Okta, Cyera, Cisco and CrowdStrike made two each. SailPoint, ServiceNow, Snowflake, Zscaler, Check Point, SentinelOne, Akamai, Google and OpenAI are among the other buyers.

How much did Palo Alto Networks pay for CyberArk?

Palo Alto Networks reported total purchase consideration of $21.1 billion in its 10-K for the fiscal year ended 31 July 2026. CyberArk shareholders received $45.00 in cash and 2.2005 Palo Alto Networks shares per share. The deal closed on 11 February 2026.

How much did Cisco pay for Astrix Security?

Cisco did not disclose terms. Calcalist reported a price of about $400 million, and the Agent Security Map labels that figure "reported" rather than filed. Cisco announced the deal on 4 May 2026, and it closed on 29 June 2026.

Is non-human identity still a separate security category?

Not as a buying category. Astrix, Entro, Oasis and Permiso were all acquired by identity or data platforms in 2026. The problem remains, but most buyers will now get NHI discovery and governance from their identity governance, privileged access or data security vendor.

What happens to my contract if my agent security vendor gets acquired?

Your contract usually continues, but the product name, renewal pricing and roadmap can change. Protect AI's open-source LLM Guard repository was archived about a year after Palo Alto Networks closed the deal. Negotiate change-of-control termination rights and renewal price caps before you sign.

Get new AI Security & Agents writing

Enjoyed this? Subscribe and tell us what you read most. AI Security & Agents is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks