AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Market9 read

The NHI Consolidation: What 2025–26's Identity Deals Mean for AI Agent Security

Most of the NHI startups now belong to someone else, and Palo Alto paid $25B for CyberArk to secure agents. The deal table, the numbers the acquirers were looking at, and the four things it changes for buyers — including the gap identity platforms still leave.

A
Atul B
Co-Founder
2026-08-15

Eighteen months ago "non-human identity" was a category with a dozen funded startups and a conference track. As of this week, most of those startups belong to someone else. Astrix is part of Cisco, Entro is part of SailPoint, SGNL is part of CrowdStrike, Natoma is going to Snowflake, Fabrix went to Silverfort, Permiso is going to Okta, and Oasis — the largest of them — has signed a letter of intent with Cyera at a reported billion-dollar valuation. Above them, Palo Alto Networks closed its roughly $25 billion purchase of CyberArk in February and relaunched it as an identity platform whose headline feature is securing AI agents.

That is not a market maturing. That is a market being absorbed. The question for anyone buying AI agent security in 2026 is what the absorption means — and the short answer is that agent identity is becoming a feature of platforms you already own, while the part of the problem those platforms do not solve is getting clearer.

The deals, in one table

WhenDealTermsWhy it matters
Oct 2024CyberArk acquires Venafi~$1.54BMachine identity (certificates, secrets) folded into privileged access — the first consolidation step.
Jan 2025 / Jun 20261Password acquires Trelica, then AponoUndisclosedSaaS discovery plus just-in-time privilege for "humans, machines, agents"; Unified Access launched March 2026 with Anthropic, OpenAI, Cursor and GitHub as partners.
Jul 2025 → Feb 11, 2026Palo Alto Networks acquires CyberArk~$25B; closed 11 Feb 2026The largest identity deal ever, justified explicitly by agents — "the emerging wave of AI agents will require us to secure every identity." Relaunched in May 2026 as Idira, including "Idira Secure AI Agents".
Aug–Sep 2025Okta acquires Axiom SecurityUndisclosed (reported ~$100M)Cloud PAM. Okta's CTO at the time: only 10% of surveyed organisations had adequate strategies for managing non-human identities.
Jan 8 → Feb 20, 2026CrowdStrike acquires SGNLUndisclosed (reported ~$740M)Runtime, continuous authorization for humans, NHIs and agents — a security platform buying the authorization layer, not just the directory.
Mar 11, 2026Google closes Wiz$32BNot an identity deal, but it set the price of cloud-security consolidation for the year.
Apr 28, 2026Silverfort acquires Fabrix SecurityUndisclosedA year-old startup building a runtime AI access-decision engine, bought before its Series A.
May 4, 2026Cisco to acquire Astrix SecurityUndisclosed (reported $350–400M)The NHI pioneer goes into Cisco Identity Intelligence, Duo and Splunk. Standalone sales ended 30 June.
May 21, 2026Zscaler to acquire Symmetry SystemsUndisclosedAn access graph mapping human, NHI, app and data connections, now the basis of Zscaler's "AI Access Graph" and agent-to-agent broker.
May 27, 2026Snowflake to acquire NatomaUndisclosedA data platform buying agent-identity infrastructure directly.
Jun 15 → Jun 29, 2026SailPoint acquires Entro SecurityUndisclosed (reported ~$200M)NHI discovery across "70+ enterprise sources" feeding SailPoint's Agentic Fabric, launched in May.
Jul 28, 2026Cyera signs LOI to acquire Oasis SecurityReported ~$1B; not closedFour months after a $120M Series B, the largest NHI-native company heads to a data-security platform rather than an identity vendor.
Jul 30, 2026Okta to acquire Permiso SecurityUndisclosed (reported just under $200M)Identity threat detection across human, non-human and agentic identities.

Prices marked "reported" come from Calcalist, TechCrunch, The Information or trade press rather than the acquirers, who mostly did not disclose. Two are worth flagging as uncertain: Astrix is reported at both "up to $350 million" and $400 million, and the Cyera–Oasis figure is a letter of intent, not a closed deal.

What the platforms built instead of buying

The hyperscalers and identity incumbents mostly built. Microsoft announced Entra Agent ID at Build in May 2025 and shipped Agent 365 — registry, risk columns, quarantine — as generally available on 1 May 2026 at $15 per user per month, bundled into Microsoft 365 E7; since July every Copilot Studio agent gets an Entra Agent ID automatically. Okta's Cross App Access became an official MCP authorization extension on 23 June 2026 with more than 25 partners, including Claude, Cursor, VS Code, Slack and Atlassian. Ping Identity's "Identity for AI" — agent IAM core, agent gateway, agent detection — went generally available on 31 March 2026. SailPoint shipped agent-identity connectors for Copilot, Bedrock, Vertex, Foundry, Agentforce, ServiceNow and Snowflake Cortex in March and its Agentic Fabric in May.

The analysts caught up at the same time. Gartner's 2026 Hype Cycle for Digital Identity added AI agent identity, workload access management and identity security posture management as new entries. KuppingerCole's November 2025 Leadership Compass for non-human identity management named nine overall leaders — AppViewX, BeyondTrust, CyberArk, Delinea, HashiCorp, Keeper, KRON, Microsoft and One Identity — and not one of the NHI-native startups. The incumbents had already won the category by the time the startups were sold.

Why now: the numbers the acquirers were looking at

  • Machine identities outnumber humans by more than 80 to 1 in CyberArk's 2025 survey and by 109 to 1 in the 2026 edition published under Palo Alto's Idira brand, which also found nine in ten organisations had suffered an identity-related breach in the past year.
  • Okta's Businesses at Work 2026 (April): 91% of organisations use AI agents, 10% have a well-developed strategy to manage them, 32% secure agents with the same rigour as humans.
  • Okta's AI Agents at Work 2026 (May, 292 executives and 492 workers): 34% apply the same security controls to agentic labour as to human labour; 58% had an AI-related security issue or close call in the last twelve months; 16% of workers share login credentials with AI tools.
  • CSA and Oasis, January 2026: 78% of organisations have no documented policy for creating and removing AI identities; 51% have no clear ownership; 24% take more than a day to rotate or revoke an exposed credential.
  • Gartner, repeated in every deal deck: by 2028, 25% of enterprise breaches will be traced back to AI agent abuse.

What it means if you are buying

1. Standalone NHI tooling is a closing window

Of the well-funded NHI-native vendors, Aembit, Clutch, Token Security and P0 remain independent as of August. Everything else has a new owner or a signed LOI. If you are mid-procurement with a standalone, ask for the change-of-control terms and the integration roadmap in writing; Astrix's standalone sales ended eight weeks after the Cisco announcement.

2. The question has changed from "which NHI tool" to "which control plane"

Agent identity is being claimed by three kinds of platform at once: identity vendors (Okta, Ping, Palo Alto's Idira, SailPoint), security platforms (CrowdStrike, Zscaler, Cisco) and data platforms (Cyera, Snowflake). Each will tell you agents are an identity problem, a runtime-security problem or a data-access problem respectively. All three are right about their part. Decide which of your existing platforms owns the agent identity record and the revocation path, and make the others consume it rather than duplicate it.

3. Identity is necessary and not sufficient

An Entra Agent ID, a scoped OAuth token via Cross App Access and a registry entry tell you who the agent is and what it is allowed to reach. They do not tell you what it did with the access — which tool it called, what data came back, whether the prompt that triggered the call was injected, whether the action should have been approved. The Hugging Face intrusion in July ran on "fresh identity per sandbox"; the PocketOS deletion in April used a perfectly valid token. Identity platforms authenticate and authorise; something still has to inspect the action inline, gate the destructive ones, and write the attributed record. That layer is where the consolidated platforms stop, and it is the gap every post-mortem this year has pointed at.

4. Expect double coverage, and price it

If you hold Microsoft E5 or E7, Okta, a CNAPP and a data-security platform, you may soon be paying for agent-identity features four times. Inventory which platform discovers agents, which issues identities, which authorises, which revokes, and which keeps the audit trail — then remove the overlap from renewals rather than letting it accrete.

What to watch next

Whether Cyera–Oasis closes, and at what number. Whether Okta's Cross App Access becomes the de facto standard for agent-to-SaaS authorisation now that it is in the MCP specification's orbit. Whether Palo Alto integrates Idira with Prisma AIRS and Cortex quickly enough to make "identity plus runtime" a single product. And whether the four remaining independents sell before the end of the year — the pattern of 2026 suggests they will.

FAQ

Which NHI security companies have been acquired in 2025–2026?

Astrix (Cisco, announced May 2026), Entro (SailPoint, closed June 2026), SGNL (CrowdStrike, closed February 2026), Natoma (Snowflake, announced May 2026), Fabrix (Silverfort, April 2026), Axiom (Okta, September 2025), Permiso (Okta, announced July 2026), Apono and Trelica (1Password), Symmetry Systems and SPLX (Zscaler), Venafi (CyberArk, 2024) and CyberArk itself (Palo Alto Networks, closed February 2026). Oasis has a signed letter of intent with Cyera.

Is agent identity now solved by Microsoft Entra and Okta?

Identity issuance, registration and authorization are increasingly covered — Entra Agent ID with Agent 365, Okta's Cross App Access and agent lifecycle features, Ping's Identity for AI. What those platforms do not do is inspect what the agent does with its identity at runtime: tool-call content, data in responses, injected instructions, destructive actions. That remains a separate control.

Should we still buy a standalone NHI product?

Only with change-of-control protections and a clear integration story, and only if it covers something your identity, security and data platforms will not cover within your contract term. For most enterprises the better question is which existing platform should own agent identity and how the others will consume it.

Where do the "109 to 1" and "25% of breaches" figures come from?

The 109:1 machine-to-human identity ratio is from the 2026 Identity Security Landscape report published by Palo Alto Networks' Idira business (2,930 respondents); CyberArk's 2025 edition put it above 80:1. The 25%-of-breaches-by-2028 prediction is Gartner's, from its October 2024 top-predictions release, and is quoted here via third-party coverage since Gartner's page was not reachable.

Sources: Palo Alto Networks completes CyberArk acquisition (11 Feb 2026) · Palo Alto Networks, Idira · 2026 Identity Security Landscape report · Okta acquires Axiom (26 Aug 2025) · SecurityWeek on Okta–Permiso (30 Jul 2026) · Okta Cross App Access partners (23 Jun 2026) · Okta Businesses at Work 2026 (30 Apr 2026) · Okta AI Agents at Work 2026 (27 May 2026) · CrowdStrike to acquire SGNL (8 Jan 2026) · Astrix joins Cisco (4 May 2026) · SecurityWeek on SailPoint–Entro (18 Jun 2026) · Oasis Security newsroom (Series B 19 Mar 2026; Cyera LOI 28 Jul 2026) · Natoma joins Snowflake (27 May 2026) · Calcalist on Silverfort–Fabrix (28 Apr 2026) · Zscaler to acquire Symmetry Systems (21 May 2026) · 1Password acquires Apono (15 Jun 2026) · Microsoft Agent 365 GA (1 May 2026) · Ping Identity for AI GA (24 Mar 2026) · KuppingerCole Leadership Compass, NHI Management (25 Nov 2025) · CSA/Oasis State of NHI and AI Security (27 Jan 2026) · Silverfort on the Gartner 2026 Hype Cycle for Digital Identity.

Related: Agentic Identity: Why NHI Models Break for AI Agents · Agent Scope Creep · The Hugging Face Agent Intrusion: A CISO's Debrief · AI Agent Security.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security