AI agents are increasingly being designed to access enterprise data, use business tools, interact with applications, and take actions with limited human intervention. That shift is creating a new cybersecurity challenge: companies must now secure not only their employees and software, but also autonomous systems that can act on their behalf.
Against this backdrop, Cyera is accelerating its expansion into AI and data security with a fresh $400 million investment from Goldman Sachs Alternatives. The funding extends the company’s Series G round and comes as Cyera broadens its platform beyond traditional data protection to address the security challenges created by AI agents and non-human identities. The company plans to use the new capital to advance its AI security capabilities, strengthen its presence in the U.S. federal market, and support continued expansion across EMEA and APAC.
But the bigger story is not simply how much money Cyera has raised. It is why AI-agent security is becoming an important enterprise security issue. As agents gain access to sensitive information and the ability to call tools or perform actions, organizations need greater visibility into what these systems can access and what they actually do. Cyera’s Agent Guardian is designed around this problem, providing visibility, governance, and runtime controls for AI agents.
At Technology Moment, we explore what Cyera’s latest funding means for the rapidly evolving intersection of AI, cybersecurity, data protection, and the agentic enterprise—and why AI agents could reshape the security market.
Cyera Raises $400M From Goldman Sachs
Cyera has secured an additional $400 million investment from Goldman Sachs Alternatives, further accelerating its expansion from data security into the rapidly developing field of AI security. Announced on September 22, 2026, the financing extends the company’s existing Series G round, which was led by Evolution Equity Partners after Cyera reached a $12 billion valuation in June. The latest capital is expected to help Cyera advance its AI security product roadmap, strengthen its presence in the U.S. federal market, and expand operations across EMEA and APAC.
The latest investment is important not only because of its size, but also because of where Cyera is positioning its business. The company originally built its reputation around data security, helping enterprises discover sensitive information, understand where it is stored, identify who or what can access it, and manage data-related risks. As businesses increasingly introduce generative AI and autonomous systems into their workflows, Cyera has expanded its focus toward AI cybersecurity, particularly the security of AI agents that can interact with enterprise data and applications.
Cyera’s strategy now connects data security, identity security, and AI agent security. Its platform is designed to help organizations understand not just where sensitive data exists, but also which human users, machines, and AI agents can reach that information. This becomes increasingly relevant as enterprises deploy AI agents capable of using tools, accessing databases, interacting with applications, and taking actions with limited human involvement.
The funding also comes at a time when AI security startups and enterprise cybersecurity companies are attracting attention around the risks created by rapidly expanding AI adoption. For Cyera, the Goldman Sachs investment provides additional resources to develop its AI security products while expanding its presence in international markets. Rather than viewing the $400 million as simply another cybersecurity funding headline, it offers a useful window into a broader industry shift: AI agents are creating new requirements for enterprise security, governance, identity management, and data protection.
What Is Cyera and How Does Its Cybersecurity Platform Work?
Cyera is a cybersecurity and data security company focused on helping organizations understand, protect, and govern access to sensitive enterprise information. Its platform is designed around the idea that modern businesses need visibility into their data environment before they can effectively manage security risks. Cyera says its technology helps security teams discover their data attack surface, control how data is used, monitor activity, detect risks, and remediate problems.
At the center of Cyera’s offering is data security. Large organizations often store information across cloud services, software-as-a-service applications, databases, endpoints, and other environments. That makes it difficult for security teams to maintain a complete picture of what sensitive information exists, where it resides, and who or what can access it. Cyera’s platform combines data discovery and classification with identity and access context to help organizations identify exposure and make more informed security decisions.
The company’s focus has increasingly expanded toward AI security as enterprises adopt AI applications and autonomous AI agents. Cyera’s current platform describes a security model that connects data, identities, and agents. Its Agent Guardian product is designed to discover AI agents and applications, map their connections to models, tools, MCP servers, knowledge bases, and data stores, and apply governance and runtime controls. It can also monitor interactions and data access and respond to potentially risky activity.
This expansion reflects a significant change in the enterprise security environment. An AI agent may not behave like a traditional application or a human employee. It can potentially use an identity, call external tools, retrieve information, and perform actions automatically. That creates questions around AI agent access control, AI agent permissions, identity security, data protection, and AI governance. Cyera is attempting to address these issues by bringing data and identity information together so organizations can understand what an AI system can reach and how it is using that access.
Cyera’s evolution therefore goes beyond conventional data security platforms. Its current direction combines data security, enterprise AI security, identity management, and AI agent security into a broader approach for organizations adopting agentic technologies. The company’s latest funding shows how it is investing in that transition as businesses look for ways to introduce AI while maintaining visibility and control over sensitive information.
Why AI Agents Are Creating a New Cybersecurity Problem
AI agents are changing the cybersecurity conversation because they can do more than simply generate text or answer questions. Unlike many traditional software systems, modern agents can reason through tasks, use identities, call tools, access enterprise information, interact with applications, and take actions with limited human intervention. Goldman Sachs and Cyera describe this combination of autonomy and access as a major reason enterprises need new approaches to AI agent security.
The central issue is access. An AI agent becomes more useful when it can reach the information and systems required to complete its job. An enterprise agent might need access to documents, databases, APIs, cloud services, customer information, or internal applications. However, the same permissions that allow an agent to perform useful work can create significant exposure if the agent is misconfigured, compromised, manipulated, or given more access than necessary. Cyera describes this as a compounding access risk because AI agents can interact with available data at machine speed.
Security teams have historically focused on employees, applications, devices, and service accounts. The growing use of autonomous AI introduces another category of actors: non-human identities and AI agents that may need permissions across multiple systems. Organizations therefore need to know not only which users have access to sensitive information, but also which machines and AI agents can reach it and what those systems are doing with that access.
Another concern is visibility. Enterprises may have approved AI applications as well as shadow AI, where employees use unsanctioned tools or create autonomous agents outside established security processes. Cyera’s Agent Guardian is designed to discover AI and agent assets across cloud environments, SaaS platforms, browser applications, and employee workstations, while providing controls for data access and agent activity.
The emerging problem is therefore broader than simply protecting an AI model. AI agent cybersecurity involves controlling identities, permissions, data access, tool calls, actions, and runtime behavior. Organizations also need to consider threats such as prompt injection, jailbreaks, unauthorized data access, and unsafe agent actions. As businesses deploy more autonomous systems, this combination of AI governance, data security, identity security, and runtime protection is becoming an important part of enterprise cybersecurity. That is why AI agents are helping create demand for a new layer of security designed specifically for the agentic enterprise.
What Is AI Agent Security?
AI agent security is the practice of protecting autonomous and semi-autonomous AI systems from unauthorized access, misuse, manipulation, data exposure, and unsafe actions. Unlike a traditional chatbot that mainly responds to a user’s prompt, an AI agent can use identities, call tools, access databases, retrieve sensitive information, interact with applications, and perform tasks with limited human intervention. This makes AI agent cybersecurity broader than simply securing an AI model or monitoring prompts and responses. The security problem extends to the agent’s identity, permissions, connected tools, data access, and actions.
For enterprises, one of the biggest concerns is understanding exactly what an AI agent can access and what it is allowed to do. An agent may need access to business information to complete a task, but excessive permissions can increase the potential impact of an error or compromised identity. This is why AI agent access control, AI agent governance, AI agent monitoring, AI agent permissions, and AI security controls are becoming important parts of enterprise security strategies. The challenge becomes even more complicated when organizations operate many agents across cloud platforms, SaaS applications, employee devices, databases, and internal systems.
AI agent security also includes protection against threats such as prompt injection, jailbreaks, unauthorized tool use, unsafe actions, and sensitive-data exposure. Modern approaches increasingly combine AI security posture management, runtime protection, identity security, data protection, and continuous monitoring rather than treating AI as an isolated application. Gartner has also highlighted the growing gap between AI-agent adoption and governance, emphasizing the importance of visibility and runtime controls.
How Cyera Is Securing AI Agents
Cyera is expanding its traditional data security approach into AI security by focusing on the connection between AI agents, identities, data, and actions. Its strategy is based on giving enterprises visibility into the AI systems operating across their environments and then providing controls over what those systems can access and do. The company’s Agent Guardian is designed to discover AI agents and applications across cloud environments, SaaS platforms, browser applications, and employee workstations, while mapping their connections to models, tools, MCP servers, knowledge bases, and sensitive data.
A major part of Cyera’s approach is moving beyond simple prompt monitoring. According to the company, Agent Guardian tracks the wider activity surrounding an AI agent, including tool invocations, database queries, data access, and actions. This gives security teams a broader view of agent behavior and can help them identify activity that does not match an organization’s policies or the agent’s intended purpose.
Cyera organizes Agent Guardian around four areas: discover, govern, protect, and validate. Discovery provides an inventory of AI assets and their connections. Governance focuses on posture, configurations, access rights, and policies. Protection evaluates interactions, tool calls, and data access in real time, with options to alert, quarantine, or block risky actions. Validation includes testing agents against threats such as prompt injection and jailbreaks to determine whether security policies actually work during runtime.
Cyera is also connecting AI agent security with identity security. Its platform can map AI agents and other non-human identities to the data they can reach, while its identity capabilities are designed to support task-specific, downscoped access rather than relying only on long-lived permissions. This creates a broader security model in which data security, identity security, AI governance, and runtime protection work together. The company’s $400 million Goldman Sachs investment is expected to support further development of this AI security platform, alongside expansion in federal and international markets.
Why Non-Human Identities Matter for AI Agents
Non-human identities (NHIs) are becoming increasingly important as businesses deploy AI agents, service accounts, API keys, machine identities, and automated software that can access enterprise systems without being directly operated by a person. Traditional identity and access management has largely focused on human users, but AI agents can now perform tasks independently and may require credentials or permissions to interact with applications, databases, APIs, and other business resources.
This creates a new NHI security challenge. An AI agent may inherit permissions from a human user or operate through its own machine identity. If those permissions are broader than necessary, the agent could potentially reach sensitive information that is unrelated to its assigned task. The scale also matters: agents can operate continuously and make large numbers of automated requests, creating a very different security environment from a human employee manually accessing a system.
For this reason, AI agent identity cannot be separated completely from data security. Security teams need to understand not only which identities exist, but also who or what controls them, what resources they can access, and what sensitive data is exposed through those permissions. Cyera’s identity platform describes this approach as connecting every AI agent, service account, and machine identity to the data it can reach. Cyera’s acquisition of Oasis Security further strengthens this direction. The acquisition brought non-human identity management into Cyera’s broader data-security platform, allowing the company to connect information about sensitive data with the identities that can access it.
The underlying principle is relatively simple: an AI agent should receive enough access to complete its task, but not unlimited standing privileges. Cyera describes an approach where access can be scoped to what the agent needs for a particular task and then expire when that task is complete. As autonomous AI becomes more common, machine identities, non-human identities, AI agent permissions, and identity governance are therefore becoming central elements of enterprise cybersecurity.
How AI Agents Could Change the Cybersecurity Market
The rapid adoption of AI agents could expand the cybersecurity market by creating security requirements that were less prominent when AI was primarily used as a conversational or productivity tool. Modern agents can access enterprise information, use software tools, call APIs, and take actions autonomously. As a result, organizations need ways to discover these agents, understand their identities, control their permissions, monitor their behavior, and protect the data they can reach.
This is contributing to the emergence of an AI security market that goes beyond traditional model protection. New areas include AI agent security, AI security posture management, AI runtime protection, AI governance, non-human identity security, AI activity monitoring, and AI data security. Cyera’s Agent Guardian illustrates this convergence by combining agent discovery, governance, runtime controls, validation, and data-access monitoring within a broader security platform.
The potential market change is also connected to the growing number of autonomous systems inside enterprises. As more companies move toward an agentic enterprise, security teams may need to manage thousands or potentially millions of machine-driven identities and interactions rather than focusing primarily on employees and conventional applications. Goldman Sachs and Cyera have specifically described this shift as a reason for bringing data and identity controls together.
Investment activity provides another indication of growing interest. Cyera’s latest $400 million Goldman Sachs investment extends its Series G, while the company has also expanded through its acquisition of Oasis Security. Separately, the Wall Street Journal reported that cybersecurity and privacy startups raised $10.6 billion globally during the first half of 2026, reflecting broader investor attention toward security challenges associated with AI.
However, the future size of the AI cybersecurity market is not predetermined. Adoption, regulation, enterprise budgets, technological development, and the actual security impact of autonomous agents will influence how the category develops. What is clear is that AI agents are changing the security problem from simply protecting an AI system to controlling what autonomous systems can see, which identities they use, and what actions they can take. That shift could make AI agent security an increasingly important part of enterprise cybersecurity.
What Are the Biggest Cybersecurity Risks of AI Agents?
AI agents are changing the way businesses use artificial intelligence, but their ability to access data, use tools, and perform actions also creates a new category of AI agent cybersecurity risks. Unlike conventional software, autonomous AI agents can operate with identities and permissions, interact with databases and applications, and complete tasks without requiring a person to approve every individual action. The more access an agent receives, the more useful it can become, but excessive access can also increase the potential impact of an error, compromised credentials,l or unsafe instructions. Cyera describes this challenge as part of the growing security problem surrounding the agentic enterprise.
One major risk is excessive data access. An AI agent may be given permission to access more information than it actually needs, potentially exposing sensitive business records. Another concern is AI agent identity and access control. Agents can operate through non-human identities, service accounts, or other credentials, making it important for security teams to know exactly which agent can reach which systems and data. Cyera’s acquisition of Oasis Security is designed to connect this NHI security capability with data security, allowing organizations to understand the relationship between identities, agents, and sensitive information.
AI agents also introduce risks involving prompt injection, jailbreaks, unauthorized tool use, and unsafe actions. A manipulated instruction could potentially influence an agent into taking an action outside its intended purpose. Cyera’s Agent Guardian is designed to evaluate agent interactions, tool invocations, and data access in real time, while also supporting red-team validation against prompt injection and jailbreak techniques.
Another growing issue is shadow AI, where employees may use AI tools or agents without formal approval from security teams. These systems can create blind spots because organizations may not know which agents exist, what data they access, or what permissions they hold. Cyera’s platform aims to discover sanctioned and unsanctioned AI assets and map their relationships with identities, tools,s and data. Ultimately, the biggest challenge is visibility and control. Enterprises need to understand what AI agents can see, what they can do, which identity they use,se and whether their permissions match the task they are performing.
What Does Cyera’s $400M Funding Mean for the AI Security Market?
Cyera’s latest $400 million investment from Goldman Sachs Alternatives highlights the growing attention around AI security and the infrastructure needed to secure the agentic enterprise. Announced on September 22, 2026, the investment extends Cyera’s Series G financing, which was led by Evolution Equity in June and valued the company at $12 billion. Cyera said the new capital will support additional capabilities across its AI Security product roadmap, expansion in the federal market, and continued international growth across EMEA and APAC.
The significance of the funding goes beyond the size of the cheque. Cyera is positioning its platform around a convergence of data security, identity security, and AI agent security. As enterprises deploy autonomous AI systems, security teams need to know which agents exist, which identities they use, what data they can access, and what actions they can perform. That creates demand for technologies covering AI governance, AI agent access control, AI agent monitoring, non-human identity security, and AI runtime protection.
The funding also follows several major developments in Cyera’s business. Earlier in 2026, the company announced a $400 million Series F round, bringing its reported total funding at that point to more than $1.7 billion. In June, Cyera announced a further $600 million Series G round at a $12 billion valuation. In September, it added another $400 million through the Goldman Sachs extension. Cyera has also expanded through its $1 billion acquisition of Oasis Security, which adds non-human identity management to its platform. The combined approach connects data with the humans, machines, and AI agents that can access it.
For the wider AI security market, Cyera’s funding is one visible indicator of investor interest in solving the security problems created by enterprise AI adoption. It does not by itself determine how large the market will become. Adoption rates, regulation, enterprise spending, technical standards, and the evolution of AI agents will all influence the category. What the investment does demonstrate is that securing AI agents, enterprise data, and machine identities has become a significant area of cybersecurity development.
Cyera Funding Timeline
Cyera’s funding history shows how quickly the company has expanded from a data-security startup into a broader AI security and identity security platform. The following timeline focuses on the major publicly reported rounds and strategic developments relevant to its current position in the AI cybersecurity market.
| Date | Funding / Development | Amount | Key Detail |
|---|---|---|---|
| November 2024 | Series D | $300M | Major growth round supporting Cyera’s data-security expansion |
| May 2025 | Series E | $540M | Expanded enterprise data-security business and global growth |
| December 2025 / January 2026 | Series F | $400M | Cyera announced the round in January 2026 and reported valuation of $9B |
| June 2026 | Series G | $600M | Led by Evolution Equity; valued Cyera at $12B |
| September 2026 | Series G Extension | $400M | Goldman Sachs Alternatives investment |
| September 2026 | Oasis Security acquisition completed | $1B | Added non-human identity (NHI) security capabilities |
Note: Public databases can differ in how they count rounds and cumulative funding, so the table focuses on individually reported company announcements and major strategic events.
Frequently Asked Questions About Cyera and AI Agent Security
Why did Cyera raise $400M?
Cyera raised $400 million from Goldman Sachs Alternatives as an extension of its Series G. The company said the funding will support its AI Security product roadmap, expansion in the federal market, and international growth across EMEA and APAC.
What is Cyera?
Cyera is a cybersecurity company focused on data security, AI security, and identity security. Its platform helps enterprises discover sensitive data, understand access risks, and protect data as organizations increasingly adopt AI systems and autonomous agents.
What is Cyera Agent Guardian?
Cyera Agent Guardian is an AI security product designed to discover AI agents, map their identities, tools, and data connections, monitor interactions,s and enforce security controls. It can help organizations block risky actions and validate agents against attacks.
Why do AI agents need cybersecurity?
AI agents can access sensitive data, use business tools, and perform actions autonomously. That creates risks involving excessive permissions, unauthorized access, unsafe tool use, data exposure,e and compromised or misused identities.
What are non-human identities in cybersecurity?
Non-human identities (NHIs) are identities used by machines, applications, automated software,re and AI agents rather than people. Managing these identities is increasingly important because AI agents may use credentials to access enterprise systems and sensitive data.
How does Cyera protect AI agents?
Cyera combines AI agent monitoring, data security, and identity controls. Agent Guardian can discover agents, map their access, evaluate tool calls and data interactions, enforce policies,s and block or quarantine risky activity.
How will AI agents change cybersecurity?
AI agents are expanding the cybersecurity attack surface by introducing autonomous systems that can access data and perform actions. This is increasing demand for AI governance, agent security, NHI security, data protection, and runtime controls designed specifically for the agentic enterprise.













