Cisco plans to acquire Astrix Security to protect AI agents and non-human identities


Cisco has announced plans to acquire Astrix Security to strengthen protection for AI agents, API keys, service accounts, OAuth tokens, and other non-human identities. The deal is aimed at a growing security problem inside enterprises: automated identities now act across systems faster than traditional identity tools can track them.

The acquisition matters because AI agents are moving from simple assistants to systems that can access data, make decisions, and trigger actions. If attackers compromise the credentials behind those agents, they can abuse trusted access at scale.

Cisco plans to use Astrixโ€™s technology to improve visibility, governance, lifecycle management, threat detection, and secrets protection for agentic AI and machine identities across enterprise environments.

Why Cisco is buying Astrix Security

Cisco said Astrix Security focuses on protecting the credentials that power modern systems. These include API keys, service accounts, OAuth tokens, and secrets used by applications, SaaS tools, cloud workloads, automation scripts, and AI agents.

These identities often do not receive the same controls as human users. Employees may use MFA, single sign-on, conditional access, and identity governance, while machine credentials can remain overprivileged, long-lived, poorly monitored, or forgotten after creation.

AI agents make this problem more urgent. An agent may connect to several tools at once, retrieve internal data, write code, update tickets, send messages, or call APIs. That makes access control and live monitoring essential.

At a glance

Deal detailWhat it means
BuyerCisco
TargetAstrix Security Ltd.
Security focusNon-human identity security and AI agent security
Main identities coveredAPI keys, service accounts, OAuth tokens, secrets, bots, automation, and AI agents
Planned Cisco integrationCisco Identity Intelligence, Cisco Secure Access, Duo Identity and Access Management, and SIEM workflows including Splunk
Main customer benefitMore visibility and control over agentic AI actions and machine-to-machine access

AI agents are creating a new identity problem

Ciscoโ€™s 2025 AI Readiness Index says 83% of organizations plan to deploy AI agents in the next year. It also says only 24% can control agent actions with proper guardrails and live monitoring.

That gap explains why Cisco is moving deeper into agentic identity security. Enterprises want the productivity benefits of AI agents, but many still lack a clear inventory of what agents exist, what they can access, and who owns the risk if something goes wrong.

Traditional security tools often focus on users, endpoints, and applications. AI agents add another layer. They act on behalf of people or systems, but they may not map cleanly to one employee, one device, or one fixed application.

What Astrix brings to Cisco

Astrix has spent the past five years building technology for non-human identity security. Cisco said Astrix will help customers discover and secure AI agents and non-human identities, including excessive privileges and real-time threats.

The companyโ€™s technology focuses on machine identities that connect systems together. These identities can include API keys for applications, OAuth tokens for SaaS integrations, service accounts for workloads, secrets stored in vaults, bots, and autonomous AI agents.

This gives Cisco a more direct way to secure the identity layer behind agentic AI. The goal is not only to see which agents exist, but also to understand what they do, what they access, and whether their behavior falls outside policy.

Core capabilities Cisco expects from Astrix

CapabilitySecurity value
Discovery and governanceMaps AI agent and non-human identity activity across enterprise systems.
Access and lifecycle managementHelps manage agents and credentials from creation to decommissioning.
Threat detection and responseDetects compromised credentials and out-of-policy agent behavior.
Secrets managementCentralizes protection for keys, tokens, and secrets across vaults and cloud environments.
Zero Trust enforcementHelps authenticate, authorize, and monitor non-human identities with stronger context.

How this fits into Ciscoโ€™s Zero Trust strategy

Cisco plans to integrate Astrix into Cisco Identity Intelligence. That would give security teams more context across human users, non-human identities, and AI agents inside the broader Cisco Security platform.

The company also plans to extend these capabilities into Cisco Secure Access and Duo Identity and Access Management. This would help organizations authenticate and authorize agentic identities using a Zero Trust model.

Cisco also said the intelligence can feed into Splunk or other SIEM tools. That gives security operations teams a broader view of agent activity, credential use, access patterns, and suspicious behavior.

Why non-human identities are risky

Non-human identities are necessary for modern IT. They allow cloud workloads, SaaS apps, automation pipelines, APIs, and AI agents to communicate without constant human involvement.

The risk comes from scale and weak governance. These identities can outnumber human accounts, hold broad permissions, last for years, and stay active after the original owner or business need disappears.

If attackers steal an API key or OAuth token, they may not need to break a password or bypass MFA. They can use the existing trusted path that the business already approved.

Common non-human identity risks

  • Overprivileged API keys that can access more data than required.
  • Long-lived service accounts with no expiration date.
  • OAuth tokens granted to third-party apps without regular review.
  • Secrets stored in code, scripts, or unmanaged locations.
  • Orphaned credentials left active after a project ends.
  • AI agents with unclear ownership and weak action controls.
  • Limited monitoring of machine-to-machine activity.

AI security is becoming part of Ciscoโ€™s broader platform

The Astrix deal follows Ciscoโ€™s larger push to secure AI infrastructure, AI applications, and agentic workflows. Cisco has already discussed AI Defense, agentic identity controls, Project Glasswing, Live Protect, resilient infrastructure work, and its acquisition of Galileo for AI observability.

That strategy points to a bigger platform goal. Cisco wants to connect identity, network, application, infrastructure, and observability data so customers can understand how AI agents behave across systems.

This approach could become important as AI-driven threats speed up. Cisco has also published guidance for defending against AI-enabled attacks, saying its work with Mythos changed how it models near-future attacker capabilities.

What security teams should do now

  • Create an inventory of API keys, OAuth tokens, service accounts, secrets, bots, and AI agents.
  • Assign an owner to every non-human identity.
  • Remove orphaned credentials and unused third-party app access.
  • Limit machine identities to the minimum permissions required.
  • Rotate high-risk secrets and block hardcoded credentials in code repositories.
  • Monitor non-human identity activity for unusual access, new locations, or unexpected API calls.
  • Apply Zero Trust controls to AI agents before they move into production.
  • Feed machine identity events into SIEM and incident response workflows.

Why the acquisition matters

Ciscoโ€™s planned acquisition of Astrix shows that AI security is becoming an identity problem as much as an application or network problem. AI agents need access to be useful, but that access must stay visible, governed, and limited.

For enterprises, the lesson is clear. Security teams need to treat AI agents and machine credentials as active identities, not background plumbing.

As more organizations deploy agentic AI, the ability to discover, authorize, monitor, and shut down non-human identities will become a core security requirement.

FAQ

How will Cisco use Astrix technology?

Cisco plans to integrate Astrix into Cisco Identity Intelligence and extend its capabilities into Cisco Secure Access, Duo Identity and Access Management, and SIEM workflows such as Splunk.

Why are AI agents a security risk?

AI agents can access data, call tools, and perform actions across systems. If their credentials are stolen or their behavior is not governed, attackers can abuse that access at scale.

What are non-human identities?

Non-human identities are digital credentials used by systems, applications, services, bots, automation tools, and AI agents. Examples include API keys, OAuth tokens, service accounts, and secrets.

What did Cisco announce?

Cisco announced its intent to acquire Astrix Security, a company focused on securing non-human identities and AI agents.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages