Identity Is Becoming the Control Plane for AI Security: What Two Recent Acquisitions Tell Us About the Market

Identity is becoming the new firewall in an AI-driven security landscape. As platforms consolidate IAM capabilities and AI agents introduce new machine identities, the market is shifting toward stronger governance, deeper integration, and specialized expertise. Two recent acquisitions illustrate how identity and automation are converging.

On August 27, 2026, two notable acquisitions were announced, highlighting the significant impact AI is having on the identity market. Integrity360, a European cybersecurity firm, has acquired CyberIAM, a specialist in identity solutions. Meanwhile, Socure, based in the US and known for its focus on identity and fraud, has acquired Fravity, a platform for agentic operations.

While these two deals might seem quite different at first glance, they reflect a common trend: companies are grappling with the challenge of managing an increasing number of both human and non-human identities. At the same time, AI agents are increasingly stepping in to handle tasks related to security, fraud prevention, risk management, and compliance. This shift in the landscape shows how intertwined identity management and AI technology have become in ensuring a secure and efficient operational environment.

The phrase “identity is the new firewall” neatly captures a significant shift in how we think about security. In an age when applications, data, cloud services, APIs, and even AI systems communicate across multiple networks, security is no longer just about protecting the perimeter. Instead, identity plays a crucial role in determining who can access resources and what actions they’re allowed to take. This shift means that managing identity is becoming a key means of controlling security within organizations. As we embrace this new landscape, it’s clearer than ever that understanding and protecting identities is essential to keeping our digital environments safe.

What Is Happening?

Integrity360 is making a strategic move by acquiring CyberIAM, thereby establishing a dedicated Identity Security Practice. This acquisition brings about 120 professionals from CyberIAM into the fold, and the company generates around EUR 18 million in revenue. CyberIAM specializes in areas like Identity and Access Management (IAM), Identity Governance and Administration, Privileged Access Management, and Customer IAM, and offers consulting and managed services.

With this acquisition, Integrity360’s workforce will swell to about 900 employees, and its annual revenue is expected to reach approximately EUR 230 million. This addition enhances its capabilities, especially as identity security increasingly intertwines with traditional security operations. Integrity360 already operates a global Security Operations Center (SOC) that provides managed security and Managed Detection and Response (MDR) services, and integrating identity services into this model is the next logical step.

On another front, Socure is taking a unique approach by focusing on digital identity verification, fraud, and risk management. It has acquired Fravity, an innovative platform that uses AI agents to automate workflows for fraud, risk, and compliance. The integration of Fravity into Socure’s RiskOS platform, branded as “RiskOS Agents,” is expected to significantly enhance its offerings.

Additionally, Socure has successfully raised USD 156 million in new funding, elevating the company’s valuation to USD 5.2 billion. Together, these acquisitions illustrate two significant trends: the expanding scope of identity security and the shift toward more autonomous identity operations.

The recent deals are noteworthy and provide strategic value, but it’s important not to mistake them for large-scale consolidation. For instance, CyberIAM brings in about EUR 18 million in annual revenue for Integrity360, though the financial details of the acquisition of Fravity haven’t been disclosed. What matters most isn’t the size of the transactions; it’s the valuable capabilities being secured. CyberIAM offers specialized expertise in identity management, while Fravity focuses on efficient workflow automation. Together, these acquisitions enhance the overall strengths of the companies involved.

Why Is This Strategically Important?

Identity has always been a central focus of security. With the rise of cloud services, SaaS, and the Zero Trust security model, the importance of Identity and Access Management (IAM) and Privileged Access Management (PAM) has grown significantly. Now, with the help of AI, this shift is accelerating even further.

The identity market is undergoing significant changes, with a growing focus on platforms. For instance, Microsoft has seamlessly integrated identity features into its Entra product, enhancing its cloud and productivity offerings. On the other hand, Google Cloud not only provides Identity and Access Management (IAM) but is also expanding these services to cover users, workloads, and even AI agents.

A clear indication of where identity security is headed is evident in Palo Alto Networks’ acquisition of CyberArk. This move signals that securing identities, whether human, machine, or AI agent, is a fundamental part of modern cybersecurity strategies.

Additionally, Google’s acquisition of Wiz adds weight to the platform dynamics, although Wiz focuses more on cloud and AI security than on IAM. Meanwhile, Okta stands out as an independent identity provider, using its unique position to differentiate itself in the market, particularly in handling identity and governance for AI agents.

This platformization trend is explored further in PAC’s InBrief Analysis of Microsoft’s evolving AI security strategy, which examines how AI agents and broader security-platform integration are changing competitive boundaries.

It’s no longer just about assigning identities and permissions to employees, customers, administrators, applications, and devices. We now have AI agents that are emerging as a new category of digital participants. These agents can:

  • access data,
  • make API calls,
  • run applications,
  • execute transactions,
  • and even coordinate with other agents.

As these AI agents become more prevalent, they will also need their own identities, access rights, policies, and clear accountability. This evolution is reshaping how we think about security and identity management in the digital landscape.

The core question is therefore changing. It is no longer only:

Which user may access which resource?

It increasingly becomes:

Which human or machine identity may perform which action under which conditions?

In recent times, we’ve seen an increased blending of various cybersecurity areas, such as IAM, PAM, machine identity security, API security, data security, and AI governance. This shift is reflected in the Integrity360-CyberIAM deal, which signals that major security firms are starting to recognize identity management as a crucial part of their services. This goes beyond just managing user identities; it now also includes machine identities and even AI agents.

Take Socure’s recent acquisition as another example. It highlights a key trend: AI agents not only need protection themselves but are also becoming integral to our approach to security and risk management.

Fravity’s ability to automate fraud, risk, and compliance processes is a strategically relevant addition to Socure’s RiskOS environment. Rather than merely offering suggestions, AI is evolving to take on more active roles in executing tasks.

This shift is important. There’s a difference between a copilot that offers analysis and recommendations and an agent that takes action. While this advancement opens new avenues for automation, it also heightens the need for effective identity management, robust authorization protocols, governance, and the ability to audit actions.

What Does This Mean for Software Vendors?

For software vendors, two recent acquisitions highlight two key priorities that are increasingly important: expanding identity platforms to include non-human entities and integrating automated execution into security and risk processes.

The deal between Integrity360 and CyberIAM underscores the first point. Identity and access management (IAM), identity governance and administration (IGA), and privileged access management (PAM) systems can no longer focus solely on people, employees, administrators, and customers. AI agents, workloads, service accounts, APIs, and other machine identities now play a much larger role in an organization’s identity landscape.

For vendors in the IAM and PAM space, this means broadening their capabilities to include:

  • machine identity discovery,
  • ownership,
  • lifecycle management,
  • short-lived credentials,
  • just-in-time access,
  • secrets management,
  • and policy-based authorization.

AI agents will also need tighter integration with cloud platforms, data systems, APIs, and enterprise applications, since their permissions are directly tied to the actions they can take.

The governance challenge extends beyond identity provisioning itself. PAC’s Expert View on the behavior of AI agents examines why controllability, transparency and auditability become increasingly important as agents gain greater operational autonomy.

The competitive landscape for workforce Identity and Access Management (IAM) is increasingly difficult to navigate. For many customers who have already adopted major platforms like Microsoft or Google, there’s a wide range of identity functionality built right in. This means they can avoid the hassle and costs of adding a separate IAM solution. For smaller vendors, it’s no longer enough to offer only basic authentication or access features. They need to stand out through:

  • strong partnerships within the tech ecosystem,
  • seamless integration with existing platforms,
  • and a distinct area of expertise.

One effective way to achieve differentiation is through vertical expertise. Industries and environments such as:

  • industrial and nuclear operations,
  • healthcare and medical technology,
  • aviation,
  • government,
  • and defense

often operate in regulated environments with stringent security requirements. These sectors may have complex needs, such as managing privileged access, integrating with legacy systems, or complying with specific regulations. In these cases, the right know-how, robust integration capabilities, and support services can be far more impactful than simply matching features in larger, bundled solutions.

This scenario presents both opportunities and challenges. Traditional identity vendors can leverage their established governance roles to strengthen AI agent security. At the same time, machine identity specialists, cloud providers, AI platform vendors, API security companies, and broader security platforms are poised to enter this arena and compete for control of these vital functions.

The acquisition of Fravity by Socure illustrates the second priority. Vendors focused on security and risk are increasingly seeking AI that can actively execute workflows, rather than merely provide insights or recommendations. Fravity enables Socure to integrate automated processes directly into fraud detection, risk management, and compliance.

This demand for automated workflows will span various security functions, including Security Operations Centers (SOCs), exposure management, IAM, and governance, risk, and compliance (GRC). Vendors will need to make critical decisions about which processes can be fully automated, which require manual approval, and where autonomous actions can occur within predefined guidelines.

As the market evolves, simply adding an AI assistant to an existing product will no longer be enough. Vendors will distinguish themselves by integrating identity management, authorization, workflow context, policy enforcement, and automated actions into a well-regulated system.

These two acquisitions signal where product development is heading. Identity vendors will need to treat AI agents as integral to identity management, while security and risk providers will need to recognize AI agents as key operational players. The most robust platforms will address both areas.

Recent industry developments are reshaping how mergers and acquisitions are approached. Smaller identity companies now operate in a competitive landscape where a larger platform is increasingly important. For example, we’ve seen Palo Alto Networks integrate CyberArk and the major cloud providers embed identity features into their services.

For these specialized companies, being acquired isn’t the only option anymore. They might also:

  • pursue deep technology partnerships,
  • focus on specific verticals,
  • or position themselves as a neutral layer that works across different platforms.

These strategies could be just as crucial to remaining relevant in the market.

What Does This Mean for Enterprise Users?

For businesses today, the recent acquisitions highlight two key priorities: managing a rapidly evolving identity landscape and preparing for more autonomous security and risk management operations.

Take the Integrity360-CyberIAM deal as an example. Companies are already grappling with complex identity and access management environments. This includes managing privileged accounts, service accounts, secrets, and machine identities, all of which can create a fragmented and challenging situation. On top of that, AI agents introduce another layer of complexity. These agents often have access to applications, data, APIs, and infrastructure, and their permissions can be difficult to monitor with traditional user-centric IAM methods.

For organizations, this means it’s vital to broaden IAM, PAM, and identity governance frameworks to include AI agents and other non-human identities. Each production agent should have:

  • a unique, traceable identity,
  • clear ownership,
  • limited permissions,
  • and a managed lifecycle.

Actions requiring elevated privileges should be subject to stricter controls, and it’s crucial to log all activity for accountability.

When organizations are looking to adopt a new platform, the economics of the platform play a significant role, especially for buyers. If a company is already well integrated with Microsoft or Google tools, it often makes sense to stick with their native identity solutions. This choice tends to be the easiest and most seamless.

However, if a business is considering a different specialized platform or service, there needs to be a strong reason to do so. This could include:

  • needing advanced capabilities in areas like Privileged Access Management (PAM) or Identity Governance and Administration (IGA),
  • wanting better cross-platform oversight,
  • managing identities for machines and agents,
  • ensuring data sovereignty,
  • handling complex hybrid environments,
  • or meeting specific regulations for certain industries.

On the other hand, the Socure-Fravity acquisition reveals a different trend: businesses are increasingly leveraging AI agents not only to analyze data but also to perform tasks in workflows related to security, fraud detection, risk, and compliance. This could lead to significant efficiency gains, especially in areas with high case volumes, repetitive investigations, and clear decision-making criteria.

Processes such as:

  • fraud investigations,
  • access reviews,
  • alert triage,
  • policy enforcement,
  • and compliance checks

are clear examples of where this can be effective.

However, the shift from AI providing assistance to it being able to take independent action changes the risk landscape. Once an AI system can act autonomously, companies need to establish clear guidelines on which decisions it can make independently, when a human needs to step in for approval, and how to identify and reverse any incorrect or unexpected actions.

These two acquisitions signal a common need in enterprise architecture: the management of AI agents’ identities and actions cannot be handled in isolation. Identity, authorization, policy enforcement, auditability, and operational control must all be integrated into the same governance model.

For organizations selecting vendors, this shift also changes the criteria. It’s no longer enough to simply check whether an IAM, fraud, or security platform has AI features. Companies should evaluate whether the vendor can effectively manage AI agent identities, limit their permissions, document their decisions and actions, and ensure that these elements are fully integrated into existing governance and security operations.

What Does This Mean for the Security Market?

The recent acquisitions highlight a significant shift in how we think about security. Rather than treating identity as just one area of security, it’s becoming a central hub that connects everything. At the same time, artificial intelligence is moving beyond being an added feature in security tools and is now a vital part of daily operations.

As we move forward, it’s becoming clear that identity is the “new firewall.” This means security and control are now more about who you are than where you are connected from. In an AI-driven world, this idea isn’t limited to employees and administrators anymore; it now encompasses everything from workloads and APIs to service accounts and autonomous agents. Securing these identities is crucial for effective protection in our digital landscape.

This shift is likely to bring together areas that were once separate, such as:

  • IAM,
  • PAM,
  • machine identity security,
  • AI governance,
  • and data security.

We’re also seeing overlaps where security operations are blending with identity operations, and where fraud management is increasingly tied to cybersecurity and digital identity. Additionally, governance, risk, and compliance sectors are adopting more automated workflows.

As this convergence unfolds, there will be mounting pressure for companies to consolidate. Vendors with a strong product but operating in isolation will need to integrate their tools into more comprehensive platforms and workflows. Conversely, larger security companies and service providers might resort to acquisitions to quickly fill any gaps in their offerings.

The market is currently in a phase of both consolidation and expansion. Basic identity and access management (IAM) capabilities are becoming more standardized and, in some areas, commoditized. At the same time, the focus is shifting toward higher-value areas such as:

  • managing privileged access,
  • handling identities for machines and agents,
  • ensuring governance across platforms,
  • and navigating regulated environments.

There’s also an increasing emphasis on how identity ties into overall security operations.

From an M&A perspective, three categories are likely to become particularly attractive:

  • specialized identity vendors with deep IAM, PAM, and machine-identity capabilities;
  • technologies for controlling and governing AI agents;
  • platforms that use agents to automate security, risk, and compliance processes.

The expectations for companies looking to acquire are rising. Nowadays, it’s not just about being a smaller player in the market; having the right scale, unique skills, access to specific markets, innovative technology, and the ability to integrate with larger ecosystems will be crucial for these smaller providers to stay relevant and competitive.

Integrity360/CyberIAM and Socure/Fravity aren’t random acquisitions; they signal an important shift in the security landscape. As artificial intelligence continues to evolve, it introduces new identities, permissions, and risks that organizations must navigate. At the same time, AI also provides tools to tackle this growing complexity more effectively and with greater automation.

These changes are interconnected. As companies increasingly rely on automated IT systems, managing identities, ensuring proper governance, and implementing controlled automation become crucial. Additionally, with industry consolidation, smaller identity providers can’t focus solely on Identity and Access Management (IAM). Instead, they should carve out their niche by leveraging specialized expertise, enhancing cross-platform integration, and focusing on regulated industries. They also need to develop strong capabilities to secure not only human identities but also machine and agent-based identities.

Conclusion

Identity is becoming a central control point for securing access for both humans and non-humans as AI agents gain greater autonomy. At the same time, consolidation is raising the bar for identity providers, increasing the importance of specialist expertise, cross-platform integration, knowledge of regulated industries, and robust machine- and agent-identity capabilities.

Share via ...