On July 30, 2025, Palo Alto Networks agreed to acquire CyberArk in a cash-and-stock deal valuing CyberArk at about $25 billion. CyberArk had spent about $1.54 billion on Venafi and up to $175 million on Zilla Security during the previous 14 months, yet none of the cited announcements explained how the resulting identity, governance, and privilege controls would work together for AI agents.

Key takeaways

  • CyberArk acquired Venafi from Thoma Bravo on May 20, 2024, in a deal valued at about $1.54 billion.
  • CyberArk’s February 13, 2025 Zilla Security deal comprised $165 million in cash and up to a $10 million earn-out.
  • Palo Alto Networks agreed on July 30, 2025 to acquire CyberArk in a cash-and-stock transaction valued at about $25 billion.
  • Palo Alto reported $388 million in Q3 revenue from CyberArk and Chronosphere combined on June 3, 2026; it did not break out CyberArk’s portion.

As AI agents move from answering questions to invoking tools, changing code, and triggering workflows, Palo Alto and its peers are pulling identity security into broader platforms. The deal is a strategic capability bet on controlling those actions. A working authority layer still requires an integration plan and a documented customer deployment.

The deals span three controls; integration remains undisclosed

CyberArk added a different control in each deal before Palo Alto moved to acquire the combined company.

Venafi manages credentials that identify software and workloads. Zilla governs the entitlements an identity should hold. CyberArk’s privileged-access controls mediate access to sensitive systems. The sequence placed machine identity, governance, and privileged access inside one company before a broader security platform moved to own it.

Palo Alto later reported $388 million of Q3 revenue from CyberArk and Chronosphere combined. Because the company combined the figure, buyers cannot isolate CyberArk’s contribution or determine whether product integration drove any of that revenue.

Palo Alto’s CyberArk agreement, Cortex AgentiX launch, and Portkey agreement describe adjacent assets. None specifies how CyberArk’s privilege checks, Venafi’s machine credentials, Zilla’s governance, Cortex AgentiX’s actions, and Portkey’s gateway will share policy or revocation controls.

Cursor’s triggers make authorization recur

Apple and Cursor show why those controls may need to converge. Apple put Anthropic’s Claude Agent, OpenAI’s Codex, and MCP support into Xcode 26.3. Cursor then released Automations that can launch agents from codebase changes, Slack messages, or timers. Apple embedded agents in development; Cursor’s triggers removed the need for a contemporaneous prompt.

Cursor’s event triggers separate authorization from execution. A developer can configure an automation now; a later repository change can invoke it under different operational conditions. The agent can then pursue a goal and interact with external systems while an orchestration layer governs task flow among components. By the time the timer fires, the login screen no longer governs what happens.

Enterprise security teams must authenticate each agent, evaluate its requested operation, enforce limits, and preserve a path for interruption. They also need strong authentication and rate limits on agent interfaces because the same connections that let useful agents reach external systems give malicious bots a route in.

Security teams can review an employee’s role when that person joins a group or requests access to a system. Cursor’s code, Slack, and timer triggers create another decision whenever an event starts a task, an agent selects a tool, or an orchestration layer hands work to another component. Teams must track how many consequential decisions agents can initiate without a fresh human gesture, not only how many actors exist.

Cortex AgentiX raises the cost of opaque handoffs

Google Cloud’s Unified Security combines security operations, cloud security, threat intelligence, secure enterprise browsing, and Mandiant expertise. Palo Alto took a different route: Cortex AgentiX introduced agents that automate cybersecurity actions across multiple vendors’ platforms, and the company later agreed to acquire AI-gateway developer Portkey at a reported valuation of $120 million to $140 million.

Cortex AgentiX automates responses across vendor platforms, while Portkey mediates an agent’s interaction with models and tools. CyberArk’s controls could sit at the permission boundary. Connecting those stages would let a recommendation become enforcement with less human delay.

Buyers pay a higher audit cost when products hide that handoff. In a combined deployment, logs would need to show where Cortex AgentiX’s recommendation ended, which CyberArk policy admitted the action, and which enforcement point executed it. That boundary matters when an automated response changes code, disables an account, or triggers an external workflow.

Peer deals leave customer demand ambiguous

Okta agreed to acquire AI identity-security startup Permiso in an almost all-cash transaction valued at just under $200 million. A month later, Okta reported growing demand for AI identity security alongside fiscal second-quarter revenue of $805 million, up 11% year over year, and net income of $116 million, up 73%.

SailPoint was also reported to be acquiring Entro Security, a platform for managing non-human identities, for about $200 million. The transaction remains classified as rumored rather than confirmed, so it shows where SailPoint may want to expand without establishing that the company completed the purchase.

Okta did not separate spending on agent authorization from spending driven by AI-enabled attacks and broader cybersecurity demand. The same market coverage linked AI adoption to more attacks and higher spending at Okta and CrowdStrike. Customers may be buying more security because agents need controlled permissions, because attackers have better tools, or because both forces arrive in the same budget meeting. Revenue alone cannot distinguish those motives.

Customers need action-level production proof

Among the dated customer materials reviewed for this article, none documented an AI agent receiving scoped, temporary, or revocable credentials and producing a measured operational outcome. Apple and Cursor have documented how agents execute autonomously. The reviewed enterprise case studies do not trace how a security platform grants, limits, and revokes authority for each action in production.

Before consolidating these controls, enterprise buyers should require a production demonstration: issue an agent a scoped credential, let it invoke a tool, revoke the credential mid-workflow, and reconstruct the decision from logs. Irreversible actions still need a human checkpoint to preserve deployment accountability, auditability, traceability, and institutional trust.

If Palo Alto connects identity records, threat telemetry, policy decisions, and enforcement, customers may close gaps between systems. They would also concentrate those decisions inside one supplier. Buyers preserve leverage by requiring portable policy, inspectable logs, and interruptible enforcement across vendor boundaries.

Frequently asked questions

Who owned Venafi before CyberArk acquired it?

Thoma Bravo owned Venafi before selling it to CyberArk. Thoma Bravo had bought Venafi for $1.15 billion in 2020.

How did Venafi’s 2024 sale value compare with its prior reported purchase price?

CyberArk’s roughly $1.54 billion purchase price was about $390 million above Thoma Bravo’s reported $1.15 billion purchase price in 2020—an increase of roughly 34% based on those deal values.

What was CyberArk’s maximum disclosed outlay for Venafi and Zilla combined?

Using the disclosed values, it was about $1.715 billion: roughly $1.54 billion for Venafi plus up to $175 million for Zilla, including the potential earn-out.

Did the disclosed Palo Alto revenue figure show how much CyberArk contributed on its own?

No. Palo Alto combined CyberArk and Chronosphere in the $388 million Q3 figure, so the available disclosure does not isolate CyberArk revenue.

CyberArk’s acquisition sequence

  • May 20, 2024 — CyberArk acquired Venafi from Thoma Bravo for about $1.54 billion.
  • February 13, 2025 — CyberArk acquired Zilla Security for $165 million in cash plus up to a $10 million earn-out.
  • July 30, 2025 — Palo Alto Networks agreed to acquire CyberArk in a cash-and-stock deal valued at about $25 billion.

The $25 billion price makes that evidence consequential. When an agent changes code after its operator has left the loop, the customer must be able to reconstruct who authorized the action, which rule admitted it, how long the permission lasted, and who revoked it. Otherwise Palo Alto would centralize authority faster than the buyer can audit it.