The acquisitions in May were not about buying revenue. They were capability acquisitions, designed to give large platform vendors immediate control over the emerging security layer for the “agentic workforce.” AI security, model defense, and AI gateways are now the fastest-rising target class, and platform vendors are racing to own the category early .
Four transactions defined the month, each a window into a different facet of the AI security challenge.
Cisco acquires Astrix Security for approximately $400 million — May 4
Cisco’s announced intent to acquire Astrix Security was the month's most impactful deal. Astrix, an Israeli pioneer in non-human identity security, secures the API keys, service accounts, and OAuth tokens that AI agents use to authenticate and act at scale . Cisco framed the acquisition as a move to extend its Zero Trust architecture to the “agentic workforce.” Astrix’s capabilities are being integrated into Cisco Identity Intelligence, Duo, Secure Access, and Splunk, enabling security teams to discover, govern, and continuously monitor autonomous AI actors across the network . The final purchase price of roughly $400 million, reported by Israeli media, validated NHI governance as a platform-level control problem, not a niche add-on .
Akamai acquires LayerX for $205 million — May 14
A week later, Akamai entered a definitive agreement to acquire LayerX in an all-cash deal valued at approximately $205 million . LayerX, another Israeli firm, provides browser-based AI usage control and secure enterprise browser technology. The strategic logic was clear: with the majority of enterprise work now happening in the browser, and with employees engaging generative AI applications and AI agents directly there, Akamai needed a way to enforce AI governance and Zero Trust at that critical edge . The acquisition extends Akamai’s application security portfolio directly into user interactions with AI, with LayerX’s co-founders and team joining Akamai’s Zero Trust organization .
Zscaler acquires Symmetry Systems for $175 million — May 21
The month’s third major platform play came from Zscaler, which announced its intent to acquire Symmetry Systems for $175 million in cash and restricted shares . Symmetry Systems brings an “access graph” technology that maps every interaction between human and non-human identities and enterprise data. Combined with Zscaler’s Zero Trust Exchange, the acquired technology aims to enable real-time anomaly detection and policy enforcement specifically for AI agent communications—a blind spot that traditional identity and access management systems cannot cover . Zscaler’s move underscored the growing realization that knowing an identity is no longer enough; security teams must understand and govern how that identity behaves across the entire data landscape .
Torq acquires Jit — May 2026
Rounding out the strategic activity, Torq, an agentic security operations platform, acquired Jit, a provider of AI Context Graphs . Unlike the other deals, this was a pure-play consolidation within the AI-native security operations space. The acquisition is designed to ensure that Torq’s AI SOC Platform integrates organization-specific contextual data into its automated investigations, making agentic threat response more precise and relevant .
Beyond these headline deals, the remaining transactions in the 31-deal total further diversified the AI security landscape. Activity was concentrated in AI security, model defense, and AI gateway technologies, sectors that industry reports identify as the fastest-rising target class for platform vendors seeking early category ownership . While the individual terms of these smaller acquisitions are less publicized, their collective direction is unmistakable: the industry is methodically buying up the building blocks required to make Agentic AI safe for the enterprise.
The May transactions are best understood not as a slowdown but as a market reset. A May 2026 analysis from Lyrie.ai describes a “structural reset, not a cyclical dip,” where AI is fundamentally changing the build-versus-buy calculus in cybersecurity . The era of acquiring security vendors for broad horizontal capability is giving way to a sharp focus on AI defensibility. This is why a startup that might have commanded a peak valuation in 2023 can now be acquired for a fraction of that price, while companies with genuine AI security technology—like Astrix, LayerX, and Symmetry Systems—are commanding strategic premiums .
Strategic buyers, not private equity, are driving this transformation. In 2025’s record year, strategic buyers controlled 92% of disclosed M&A value, and that pattern has only intensified in 2026 . The race is on to own the control points that will define Zero Trust in an AI-native enterprise: the identity of the agent, its authorized behaviors, its communication pathways, and the data it can touch. May 2026 demonstrated that the biggest names in infrastructure and security are now willing to pay hundreds of millions to fill each of these specific gaps, one acquisition at a time.