Back to Learn
AI

Your AI Agents Have Keys to Everything. Who's Watching Them?

July 30, 2026

Your AI Agents Have Keys to Everything. Who's Watching Them?

By Warren Schuitema, Founder | Matchless Marketing | The AI Dad


A $1 billion acquisition just happened in the AI security world, and it's not just a Wall Street story. It's a warning for every small business owner running AI tools connected to their data.

On July 28, 2026, data security company Cyera announced it's acquiring Oasis Security for approximately $1 billion. The deal is mostly cash. Cyera is a company that was just valued at $12 billion. They didn't spend this kind of money on a trend. They spent it because the problem Oasis solves is real, it's urgent, and it's showing up in every business that's added AI agents to their stack.

Here's what that problem is: your AI agents have identities. Those identities have permissions. And almost nobody is watching them.


What "Non-Human Identity" Actually Means for Your Business

Let's get past the enterprise jargon for a second.

Every time you or someone on your team connects an AI tool to Slack, Google Drive, Salesforce, or an internal system, a new OAuth token or API key is created. That's a non-human identity. It's a credential that carries permissions and can access your data independently, without you clicking a button.

That credential carries permissions. And it's almost never added to a centralized identity inventory. AI agent sprawl refers to the rapid, uncontrolled accumulation of credentials when AI agents are granted access to your systems without IT oversight.

If you've connected ChatGPT's browsing feature to a shared drive, hooked up an n8n workflow to your CRM, or authorized a Zapier automation to read your inbox, you've created non-human identities. Probably more than you realize. You may not even remember half of them.

In a typical enterprise, non-human identities — bots, service accounts, and AI agents — outnumber human users by 100 to 1. That ratio doesn't magically disappear at the SMB level. It just means fewer people are watching a similar problem.


Why Cyera Paid $1 Billion to Fix This

Oasis Security developed a non-human identity and agentic access governance platform to address the growing use of AI agents in enterprise environments. Its Agentic Access Management (AAM) technology provides visibility, control, and policy enforcement across critical systems.

As the number of AI agents proliferates, companies must deploy cybersecurity software that monitors these agents' behavior and grants them permission to access other software.

Cyera said the acquisition of Oasis will unify identity and data security into a single platform built to handle the growing use of AI agents.

In plain terms: Cyera already knew what data companies had and how sensitive it was. Oasis knew who and what could access that data. Together, they're building a single answer to the question every business should be asking right now: what can my AI agents see, and should they be allowed to see it?

Cyera's CEO Yotam Segev put it directly: "Every identity — human, machine or agent — is a point of exposure, which is why every identity has to be tracked, understood and controlled."

This deal isn't news because the dollar amount is big. It's news because it confirms that AI agent security has crossed from theoretical concern to urgent market reality.


The Specific Risk You're Probably Ignoring

The Model Context Protocol (MCP), the standard protocol for powering agentic AI, ships with no authentication enabled by default. Nearly 38% of the 500-plus MCP servers scanned in April 2026 lacked authentication entirely.

Read that again. The default is no authentication.

For non-human identities like AI agents and other automated services, the equivalent targets are API keys and access tokens. These are the digital keys to the kingdom. If an attacker gains access to one, they can gain unauthorized access and manipulate your systems.

Sophos's State of Identity Security 2026 report, based on a survey of 5,000 IT and security leaders, found that weak non-human identity management is now the second-greatest root cause of breaches, appearing in roughly 40 percent of security incidents.

This isn't a "someday" risk. If you're running any kind of automated AI workflow, there are credentials out there with access to your business that you haven't checked in months, or ever.


What You Can Actually Do Today

You don't need a $12 billion security platform to start cleaning this up. You need 30 minutes and some honest inventory work.

Step 1: Pull your connected apps list. Go to Google, Microsoft, or wherever your core accounts live. Find the "third-party apps with access" section. Most people haven't looked at this in over a year. You're looking for anything AI-powered you've authorized, especially tools with access to files, email, or calendar.

Step 2: Check your Zapier, Make, or n8n credentials. Open your automation platform and look at every active workflow. For each one, ask: what accounts is this connecting? What data can it read or write? If you can't answer that in ten seconds, that workflow needs a review.

Step 3: Revoke anything you're not actively using. If an API key or OAuth connection is sitting there for a tool you stopped using three months ago, revoke it. A dormant credential is still a live key if it hasn't been deleted.

Step 4: Apply the principle of least privilege. When you're connecting a new AI tool, give it only the access it actually needs. Don't authorize read/write when read-only will do. Don't connect it to your entire Google Drive when a single shared folder is enough.

Step 5: Set a 90-day review reminder. This doesn't have to be a big production. A calendar reminder once a quarter to look at your connected apps and active automations is more security hygiene than most small businesses have right now.


The Cyera/Oasis deal tells you something important: the companies building AI infrastructure are taking agent security seriously enough to bet a billion dollars on it. The question is whether you're taking it seriously enough to spend 30 minutes on it.

Your agents have access to your data, your clients' data, and your business systems. They're working around the clock, which is the whole point. But they're also operating with credentials that were issued once and never reviewed.

Start the audit today. Not because a breach is guaranteed, but because you've built something worth protecting.


Warren Schuitema is the founder of Matchless Marketing and the creator of The AI Dad — a brand and platform helping small business owners and solopreneurs implement AI tools without hype, overwhelm, or a developer on retainer. He builds, tests, and documents real AI systems live so his audience can follow what actually works inside a running business. He's the operator behind a fully automated AI agent workforce managing content, leads, research, and client onboarding at Matchless Marketing — which means this isn't theoretical for him. He's running the same systems he's writing about.