In 2024, CyberArk committed about $1.54 billion to Venafi. In 2025, it committed up to $175 million to Zilla Security. The company assembled machine credentials and access governance while enterprise deployments still centered on narrow, efficiency-focused work. On July 30, 2025, Palo Alto Networks agreed to buy CyberArk for about $25 billion.
AI agents turn identity from a login question into a runtime question: what may this software do now, for whom, and with which record afterward? As agents interpret untrusted inputs and act across enterprise systems, each action requires narrowly scoped authority, controlled escalation, and an audit trail.
Action makes authorization the decisive boundary
By 2024, business software vendors were moving copilots from drafting toward taking actions on a user’s behalf. A standalone language model can return a bad answer. An agent can turn that answer into a query, modification, message, or workflow.
Attackers can plant instructions in content the agent reads. Microsoft said email spammers were using ASCII smuggling to conceal malicious instructions from platform filters. Attackers have used the same technique in prompt-injection attacks on AI agents. Documents, messages, webpages, and support tickets can carry instructions into software with permissions elsewhere.
A filter can catch a known malicious pattern, but it cannot prove that every instruction is benign. An agent that only needs to read one record should not inherit permission to alter the system containing it. An agent that may update routine fields should still encounter an approval checkpoint before an irreversible operation. Strict permissions can contain the damage even when the model misreads the input.
Enterprises therefore need grants smaller than an account: one actor, one task, one set of tools, and one policy window. Those grants keep authority temporary and give defenders a firmer backstop than asking a probabilistic model to recognize every disguised instruction.
CyberArk joined machine credentials to access governance
CyberArk extended its privileged-access base in two directions. It acquired machine-identity manager Venafi in 2024 and then bought identity-governance platform Zilla Security in 2025.
The Zilla price consisted of $165 million in cash and up to $10 million in an earn-out. Venafi establishes and manages credentials for non-human systems. Zilla determines which identities may receive access, applies policy, and supports review. CyberArk’s existing controls can stop or approve requests for privileged systems. Together, the products could verify the software actor, evaluate its entitlement, and interrupt requests that require human approval.
Each constrained agent needs temporary credentials, allowed tools, escalation rules, and revocation. Those repeated decisions connect product categories that enterprises once bought separately.
Rivals are bidding for the same software identities
Okta agreed to acquire Permiso Security in an almost all-cash deal valued just under $200 million. NewCore emerged from stealth with a $66 million seed to manage human and AI-agent identities in one system.
Both companies want to govern software actors that use credentials and entitlements without mapping neatly to employees. Vendors that already control one part of the identity lifecycle can extend into that population or let another provider occupy the policy path.
Microsoft, OpenAI, Salesforce, and other vendors still use “agent” differently, making market-size claims and product comparisons unreliable. Buyers can bypass the label by inventorying concrete capabilities—software that calls tools, systems it can reach, credentials it receives, and actions it can execute—so security teams govern the verbs rather than debate the noun.
A bot identity cannot carry accountability
Microsoft’s 37-page humanist AI code of conduct says people matter more than AI and rejects legal personhood for AI systems. Although the document sets company policy rather than law, it exposes an architectural constraint: an agent cannot be the final accountability endpoint. Every consequential action must resolve to a human or organizational principal, the authority that principal delegated, and the controls applied during execution.
Companies currently use agents primarily to improve efficiency and reduce costs rather than drive top-line growth. Companies pursuing those gains can keep permissions narrow while allowing agents to route tasks, choose tools, and take bounded steps.
Teams can specify which steps proceed automatically and which stop for review. At a checkpoint, the system can record the initiating user, machine identity, credential, policy, approver, and resulting action. The approver intervenes only when the requested authority crosses a defined threshold.
An identity provider embedded in that loop can deny authority, request approval, revoke access, and preserve evidence. The agent’s credential may be valid while its instruction is hostile, so the provider must evaluate context when the agent acts.
Palo Alto still has to make the portfolio behave as one
Palo Alto’s agreement to buy CyberArk put the identity assets beside agents that execute security work. By 2026, Palo Alto had also agreed to acquire AI-gateway developer Portkey at a reported valuation of $120 million to $140 million. It acquired Console, whose agents resolve IT support tickets, and launched Cortex AgentiX to automate cybersecurity actions across products from multiple vendors.
Palo Alto now spans machine identity, governance, model traffic, and agent execution. To turn those assets into one authority system, it must carry policy through the entire execution path:
- An agent requests a specific capability for a defined task.
- The identity layer verifies the machine actor and its initiating context.
- The governance layer evaluates entitlement, duration, and policy.
- The privileged-access layer issues narrowly scoped authority or triggers approval.
- The audit layer preserves the decision and resulting action as one trace.
Palo Alto must make every product share policy language, identity records, and audit trails. If each product keeps its own, customers still bear the integration burden, and another vendor can insert itself between the agent and the tool.
When one trace follows a request from instruction through permission to action, Palo Alto will own the right CyberArk committed $1.7 billion to assemble. Fragmented traces leave that right—and the integration work—with the customer.