The security layer is becoming the agent stack

Today’s headlines suggest that the next AI platform battle is less about making agents more autonomous than making them safe enough to admit into real companies. Cyera’s $1B Oasis deal, Spur’s $200M raise, Runlayer’s MCP lawsuit and Visa’s open-sourced Mythos harness all point to the same shift: the winners may be the companies that turn agent risk, access and evaluation into default product plumbing.

·3 min read

TechCrunch

Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents

Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents.

techcrunch.com

A billion dollars for permissions on software that does not have a payroll record. That is the cleanest way to read Cyera’s planned acquisition of Oasis Security, a deal TechCrunch reported at $1B to safeguard proliferating AI agents.

The obvious take is that agent autonomy is the next platform fight. I think that is half-right and slightly early. The nearer fight is over who gets to define the agent control plane that lets agents enter companies at all.

Autonomy is exciting in demos. Access is what makes procurement nervous.

The new control layer

Every useful agent eventually asks for something sensitive: a database credential, a Slack channel, a payment workflow, a customer record, a code repository, a browser session. The agent is only as valuable as the systems it can touch. It is also only as tolerable as the blast radius around those permissions.

That is why Cyera buying Oasis matters. The headline is an acquisition, but the product question underneath is simpler: who is this agent, what can it see, what can it do, and who is accountable when it does the wrong thing?

Spur Intelligence’s $200M raise pushes the same argument from another angle. TechCrunch reported the round for a bot-detection startup. That used to sound like fraud prevention for a web built around human sessions. Now it reads like a preview of the agent traffic problem. If software agents become normal users of products, then “is this a person?” becomes a less useful question than “what kind of actor is this, and should it be allowed here?”

The web’s old security model assumed humans clicked buttons and bots were usually abuse. Agentic systems break that clean split. A bot may be a customer’s purchasing assistant, a scraper, a fraud attempt, or an internal tool behaving badly. Product teams will need policy, telemetry and pricing models for that ambiguity. Blocking everything automated will feel as dated as blocking all API calls.

Runlayer’s fight with Rippling shows why this layer is commercially tempting. TechCrunch reported that Runlayer, an MCP startup, has accused Rippling of stealing its product idea. Whatever the legal outcome, the dispute points to a harder product truth: the agent connectivity layer is becoming valuable enough for incumbents to care.

That should make founders both excited and uneasy. Secure gateways, permission brokers, audit logs, evaluation harnesses and identity graphs may look like developer plumbing. But plumbing becomes power when it sits between models and business systems.

Visa’s Mythos work adds the missing piece: evaluation before exposure. VentureBeat reported that Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness behind the work. The interesting move is treating containment and repeatable evaluation as infrastructure others can inspect and reuse.

There is a useful parallel in payments. Credit cards did not become mainstream because merchants suddenly trusted strangers. They became mainstream because authorisation, fraud checks, dispute processes and liability rules made stranger-to-stranger commerce workable. The boring trust machinery created the market.

Agents are heading towards the same bargain. The winning products may not be the ones with the flashiest autonomy loop. They may be the ones that make a CFO, general counsel and security team say: fine, this thing can have access.

For builders, the implication is blunt. If your agent product depends on customers handing over credentials, data and workflow authority, the security layer is part of the product, not an enterprise add-on. The next agent stack will be built less around “what can it do?” and more around “what can it safely be allowed to do?”


Read the original on TechCrunch

techcrunch.com

Stay up to date

Get notified when I publish something new, and unsubscribe at any time.

More news