Tech M&A Watch: AI Infrastructure and Security Drive New Acquisitions

Written by Erwin Castro — Founder & Editor, The CODEW

Watch Tech Series · Tech M&A Watch | September 24, 2026

Daily M&A intelligence covering technology acquisitions, strategic deals, AI infrastructure, cybersecurity, cloud platforms, enterprise software, and the capabilities changing hands across the technology market.

Tech M&A Watch: AI Infrastructure and Security Drive New Acquisitions

EXECUTIVE BRIEF

Technology M&A is moving beyond conventional software consolidation and deeper into the infrastructure and security layers required to operate AI at scale. Nutanix’s acquisition of AI orchestration company Ryax Technologies and Upwind’s acquisition of AI-security startup Aegis illustrate a common strategic objective: gaining control over the software that makes AI systems more efficient, governable, and secure.

The shared deal signal is strategic capability. Nutanix is adding AI-aware compute orchestration to improve GPU use and workload placement across hybrid environments. Upwind is adding AI-security research and product capabilities as models, agents, and autonomous workflows become connected to production systems. In both cases, the buyer is acquiring a control layer around AI rather than simply buying another AI application.

M&A Theme

Companies are increasingly acquiring the layers required to make AI operational: infrastructure optimization, orchestration, identity, security, software tooling, deployment and management.

Lead Deal

AI Infrastructure M&A

Nutanix Acquires Ryax Technologies to Add AI Compute Orchestration

Buyer: Nutanix · Target: Ryax Technologies

Nutanix acquired France-based Ryax Technologies, an AI-driven compute orchestration and management company. Financial terms were not disclosed. Nutanix said it plans to integrate Ryax’s GPU-utilization and smart-scheduling capabilities into future releases of Nutanix Kubernetes Platform (NKP) and Nutanix Enterprise AI (NAI). 

Ryax adds technology around intelligent resource optimization, AI-aware workload scheduling and infrastructure management. Nutanix positions the acquisition as part of its strategy to help enterprises build, run and govern agentic AI across private data centers, hyperscalers, neoclouds and high-performance computing environments. 

The strategic asset is not another AI model or end-user application. Nutanix is acquiring part of the infrastructure-management layer that sits between AI workloads and underlying compute. As enterprises distribute workloads across private infrastructure, public cloud, GPU clouds, and HPC systems, intelligent placement and scheduling can become a differentiating capability.

Deal Intelligence Field Nutanix / Ryax Assessment
Buyer Nutanix, a hybrid multicloud and enterprise infrastructure software provider.
Target Ryax Technologies, a France-based developer of AI-driven compute orchestration and management software.
Capability GPU utilization, resource optimization, smart scheduling, and AI-aware workload placement.
Integration target Future versions of Nutanix Kubernetes Platform and Nutanix Enterprise AI.
Strategic motive Improve the efficiency, management and governance of enterprise AI workloads across hybrid infrastructure.
Transaction economics Financial terms were not disclosed. Nutanix said the acquisition is not expected to be material to its financial results. [71]

What the deal means: Nutanix is buying AI infrastructure control software. The commercial objective is to help enterprises extract more useful work from expensive and increasingly distributed compute capacity.

Why GPU Utilization Has Become an M&A Issue

AI Infrastructure Economics

Software That Improves AI Capacity Efficiency Is Becoming Strategically Valuable

AI infrastructure is expensive, and expensive infrastructure is valuable only when it is productively utilized. GPU capacity can be underused when workloads are oversized, poorly scheduled, isolated in separate environments, delayed by data or dependency constraints, or deployed without sufficient visibility into actual resource consumption.

Ryax’s platform is designed to improve this operating model through GPU and CPU optimization, AI-aware workload scheduling, automated resource management and placement decisions across hybrid environments. Nutanix said the technology will help customers optimize GPU utilization and streamline AI deployments. 

The broader M&A implication is that compute orchestration is becoming a strategic software category. As more enterprises operate AI across private data centers, hyperscalers, neoclouds, edge sites, and HPC environments, the ability to determine where a workload should run can affect performance, availability, cost, data governance, and capacity utilization.

AI Infrastructure Problem Orchestration Objective
Idle or underused GPUs Increase utilization through scheduling, workload consolidation, and resource right-sizing.
Variable workload demand Allocate capacity dynamically between training, inference, experimentation, and enterprise workloads.
Hybrid infrastructure complexity Determine where workloads should run across on-premises infrastructure, public cloud, neocloud and HPC resources.
Cost pressure Match capacity, model choice and workload-placement decisions with business value and cost constraints.
Operational resilience Automate recovery and resource reallocation when capacity constraints, workload failures, or infrastructure issues occur.

M&A signal: As AI compute becomes more expensive, software that improves utilization can become as strategically important as additional hardware capacity.

AI Security M&A

AI Security Deal

Upwind Acquires Aegis and Launches AI Security Labs

Buyer: Upwind · Target: Aegis

Cloud-security company Upwind acquired Aegis, an Israeli AI-security startup that had been operating in stealth. Upwind also launched Upwind AI Security Labs, bringing Aegis co-founders Omri Limor and Saar Ankonina into the company to lead the new research and engineering operation. 

The new lab will focus on emerging AI security threats, including AI agents, agent skills and plugins, AI-generated attacks, attack detection, security research and defensive capabilities for AI environments. Upwind describes the initiative as a response to the increasingly connected and autonomous nature of AI systems. 

The companies did not publicly disclose financial terms. Axios reported that the all-equity transaction was valued between $25 million and $50 million. That range should be treated as reported, rather than as confirmed consideration disclosed by the parties.

Deal Intelligence Field Upwind / Aegis Assessment
Buyer Upwind, a cloud security company.
Target Aegis, an Israeli AI-security startup focused on threats emerging from AI infrastructure and AI agents.
Capability AI security research, agent security, threat detection, scanning, and defensive tools for AI environments.
Talent component Aegis co-founders Omri Limor and Saar Ankonina will lead Upwind AI Security Labs. 
Strategic motive Extend cloud security into the emerging attack surface created by AI agents, autonomous workflows and AI-generated attacks.
Transaction economics Terms were not disclosed by the companies. Axios reported an all-equity valuation range of $25 million to $50 million. 

What the deal means: Upwind is acquiring both AI-security capability and specialized talent, then giving the combined team a distinct organizational mandate through AI Security Labs.

The AI Security M&A Layer

Security Platform Expansion

Security Buyers Are Acquiring AI-Specific Capabilities, Not Only Adding AI Features

The Aegis transaction reflects a broader change in cybersecurity. As AI systems become connected to tools, APIs, identities, enterprise information, cloud environments, and production workflows, security teams need to protect more than the model itself. They need to govern the systems, permissions, data flows, and automated actions surrounding the model.

This creates new M&A categories around AI agents, machine identities, non-human access, agent-to-agent interactions, AI workload monitoring, model security, AI-generated attacks, prompt and tool controls, data protection and AI-specific threat research.

The strategic signal is that cybersecurity platforms may need dedicated AI security capabilities rather than treating AI as only another feature inside an existing security product. Upwind’s AI Security Labs provides an example of a buyer using an acquisition to create a specialized research and product organization around this emerging threat category.

AI Security Layer M&A Rationale
Agent security Controls for autonomous systems that use tools, access enterprise resources, and perform actions.
Machine identity Visibility and governance for service accounts, APIs, workloads, devices and AI agents.
AI attack detection Research and controls for attacks created, accelerated, or directed by AI systems.
Model and workload security Protection of AI infrastructure, data, model access, deployment paths and runtime environments.
Governance and observability Monitoring of prompts, tools, permissions, behavior, policies, risk and audit trails across AI workflows.

The Bigger Pattern: Buying the AI Control Layer

2026 M&A Pattern

Infrastructure, Software and Identity Are Becoming AI Control Points

The Nutanix and Upwind acquisitions fit alongside other 2026 transactions that target layers required to make AI useful in enterprise environments. The common objective is not necessarily to own the model. It is to own a critical capability around AI deployment, identity, software portability, orchestration, or security.

Acquisition Buyer Strategic Capability
Ryax Technologies Nutanix AI compute orchestration, GPU utilization, workload scheduling and hybrid AI management. 
Aegis Upwind AI security research, agent security, AI attack detection, and specialist security talent. 
Permiso Security Okta Threat detection and mitigation across human, non-human, and agentic identities in multi-cloud environments. Okta closed the acquisition on August 26. 
Modular Qualcomm AI-native software infrastructure for generative and agentic AI across data-center and edge environments. Qualcomm completed the acquisition in July; Reuters reported the all-stock deal at nearly $4 billion. 

Okta’s acquisition of Permiso was aimed at identity threat detection and response across human, non-human and agentic identities. The platform is intended to add identity-risk signals, behavioral analytics and detection capabilities to Okta’s identity architecture. 

Qualcomm’s acquisition of Modular shows the same control-layer thesis on the infrastructure side. Modular gives Qualcomm AI-native software infrastructure intended to support generative and agentic AI across data-center and edge systems, strengthening Qualcomm’s software foundation beyond the chip itself. 

Recurring theme: Companies are acquiring the software, infrastructure, and security layers needed to make AI operational—not only the applications that users see.

From AI Applications to AI Infrastructure

Strategic Market Shift

The Next AI M&A Layer Is Operational Infrastructure

The first major phase of AI dealmaking was often associated with applications, foundation models, and talent. The next strategic layer is increasingly operational: how AI is deployed, connected, governed, secured, observed, optimized, and integrated with enterprise systems.

AI Infrastructure

Orchestration

Security

Identity

Deployment

Management and Governance

A company does not necessarily need to acquire an AI model developer to strengthen its AI position. It may instead acquire the software that improves GPU efficiency, the identity platform that governs agents, the observability tools that monitor AI workflows, the security research team that detects AI attacks, the data platform that supplies enterprise context, or the deployment layer that makes multiple models usable in production.

This changes the M&A environment. A relatively small infrastructure or security target may be strategically important because it fills a gap that blocks a larger platform from delivering enterprise AI at scale.

AI Operating Layer Potential Acquisition Target Type
Compute efficiency GPU orchestration, workload scheduling, capacity management, inference optimization, and FinOps software.
Security AI agent protection, threat research, model security, attack detection and AI security posture management.
Identity Machine identity, agent identity, non-human access, secrets management and privileged access controls.
Data and context Data platforms, retrieval systems, AI data governance, connectors, labeling and domain datasets.
Deployment and operations Model gateways, agent runtimes, observability, evaluation systems, workflow platforms and infrastructure automation.

Build vs Buy

Strategic Acquisition Logic

Why Nutanix and Upwind Bought Rather Than Built

Nutanix could have expanded its AI infrastructure management capabilities entirely through internal product development. Instead, it acquired an existing AI compute orchestration platform and team, accelerating access to GPU utilization and smart-scheduling capabilities intended for NKP and NAI. That decision suggests the technology and specialized expertise were sufficiently mature and strategically useful to justify acquisition. 

Upwind could have built a dedicated AI-security research group internally. The Aegis acquisition instead gives it a specialized founding team, a technology base, and an immediate organizational structure for AI Security Labs. The structure indicates that talent and research depth are part of the strategic asset, not simply an adjunct to a product acquisition. 

In both cases, buying offers speed. But the deeper rationale is control: Nutanix can embed orchestration into its platform roadmap, while Upwind can shape AI-security research and capabilities inside its cloud-security architecture.

Build vs. Buy Factor Nutanix / Ryax Upwind / Aegis
Speed Adds established orchestration capabilities to the AI infrastructure roadmap. Creates a dedicated AI-security research operation immediately.
Technology GPU utilization, scheduling, placement, and resource optimization. AI security, attack detection, scanning, and agent-focused security capabilities.
Talent Specialized compute-orchestration engineering and product expertise. Founders and specialist AI-security researchers who will lead the new lab.
Control Embeds infrastructure management directly into Nutanix AI platform releases. Brings AI-security research and product direction inside Upwind’s platform strategy.
Integration challenge Translate orchestration technology into a coherent hybrid-cloud customer experience. Convert research and emerging capabilities into scalable security products and measurable customer outcomes.

M&A Economics

Deal Economics Watch

Capability Can Matter More Than Headline Purchase Price

The current transactions show why M&A analysis should not depend entirely on disclosed transaction value. Nutanix did not disclose the price for Ryax. Upwind did not disclose terms for Aegis, although Axios reported an all-equity valuation range of $25 million to $50 million. The strategic importance of both deals comes from the capabilities being acquired, the platform integration plans and the market layers they address. 

Transaction Economics Primary Strategic Asset
Nutanix / Ryax Financial terms undisclosed; Nutanix said the deal is not expected to be material to financial results.  AI compute orchestration, GPU utilization and hybrid workload management.
Upwind / Aegis Terms undisclosed by the parties; Axios reported an all-equity valuation range of $25 million to $50 million.  AI-security technology, specialized research team, and AI Security Labs leadership.
Okta / Permiso Terms were not publicly disclosed by Okta; outside reporting placed the value at just under $200 million.  Identity threat detection across human, non-human, and agentic identities.
Qualcomm / Modular All-stock transaction reported by Reuters at nearly $4 billion; Qualcomm completed the acquisition in July.  AI-native software infrastructure spanning data-center and edge AI environments.

Reporting standard: Disclosed deal value, reported estimates, and strategic interpretation should remain separate. An undisclosed transaction should be reported as undisclosed even when its commercial rationale is clear.

What This Means for Technology M&A

M&A Themes

The AI Stack Is Becoming a Target for Strategic Consolidation

Several themes are visible across the current deal environment:

Infrastructure optimization AI infrastructure companies are acquiring or building software that improves compute utilization, deployment efficiency, and workload placement.
AI security Cybersecurity vendors are acquiring specialized capabilities for AI agents, machine identities, autonomous workflows, and AI-generated attacks.
Software infrastructure Chip companies and enterprise platforms are targeting software layers that can strengthen their AI ecosystems beyond hardware alone.
Vertical integration Technology companies increasingly seek control across multiple layers of the AI stack, from chips and cloud capacity to orchestration, identity and security.
Talent acquisition Specialized AI engineering, infrastructure and security talent remains a strategic asset, particularly when paired with product technology and research capability.

The CODEW M&A Framework

Tech M&A Watch evaluates significant transactions through eight core questions:

Buyer Who is acquiring, and what strategic direction has that company established?
Target What company, team, product, technology, or data asset is changing hands?
Capability What does the target actually add to the buyer’s infrastructure, software, or security stack?
Strategic Motive Why does the buyer need this capability, and why does it matter now?
Integration Where will the technology, team, or product be incorporated inside the buyer?
Competitive Impact Which competitors, customers, partners, or suppliers may be affected?
Build vs Buy Why did the buyer acquire instead of building, licensing, or partnering for the capability?
Market Signal What does the transaction reveal about where technology markets and AI control layers are moving?

M&A Watchlist

1. AI infrastructure GPU orchestration, capacity management, AI FinOps, workload placement, inference optimization, and hybrid AI operations.
2. AI security Agent security, AI-generated attack detection, model security, AI posture management and AI security research platforms.
3. Machine identity Non-human identity, agent identity, API access, privileged access, and secrets-management capabilities.
4. AI observability Agent tracing, model evaluation, tool-call monitoring, AI cost visibility and policy enforcement.
5. Developer and AI software tools Model deployment, compilers, inference runtimes, agent development platforms and AI application tooling.
6. Data infrastructure Training data, retrieval, storage, governance, data pipelines and enterprise AI context layers.
7. Robotics and physical AI Robot foundation models, edge AI, simulation, autonomy, perception, controls and industrial robotics platforms.
8. Semiconductor software AI compilers, EDA, system software, networking software and tools that help heterogeneous compute operate efficiently.
9. Strategic buyers Hyperscalers, semiconductor companies, enterprise software platforms, cybersecurity vendors, infrastructure providers and private-equity firms expanding AI capabilities.

Related CODEW Coverage

AI Infrastructure WatchCompute Orchestration, GPU Utilization and the Economics of AI Capacity
Cybersecurity WatchAI Agents, Identity and the Expanding Enterprise Attack Surface
Cloud Computing WatchHybrid AI Infrastructure, Sovereign Cloud and Agent-Native Operations
Infrastructure Software WatchAI Operations, Scheduling, Observability and Infrastructure Automation
Semiconductor WatchAI Software, Accelerators and the System-Level Compute Stack
Build vs BuyWhy Technology Companies Buy Critical AI Capabilities
M&A Intelligence HubTechnology Acquisitions, Strategic Deals and Market Consolidation

The Tech M&A Watch Takeaway

The latest transactions show that AI M&A is moving deeper into the operating stack. Nutanix is acquiring technology intended to make AI infrastructure more efficiently managed. Upwind is acquiring AI-security capability as agentic systems and AI-generated attacks create new security requirements. Okta and Qualcomm provide supporting examples of companies buying identity and software infrastructure around AI.

The central M&A question is becoming less about who will buy the next AI application and more about which companies will acquire the infrastructure, software and security capabilities needed to control the AI economy.

THE CODEW · TECHNOLOGY INTELLIGENCE

Editorial Note

The Newsroom reports which deals were announced. Tech M&A Watch analyzes the capabilities, technologies, talent, infrastructure, customer relationships and market positions changing hands through acquisitions and strategic transactions. This edition examines Nutanix’s acquisition of Ryax Technologies, Upwind’s acquisition of Aegis, and the broader pattern of AI infrastructure, identity, and security acquisitions.

Deal terms and valuation figures may be undisclosed or based on attributed third-party reporting. Nutanix did not disclose financial terms for Ryax. Upwind did not disclose financial terms for Aegis; the reported $25 million to $50 million range is attributed to Axios. Educational content only. Not investment, legal, tax, accounting, merger-arbitrage, cybersecurity, or procurement advice. Product capabilities, transaction status, and market conditions can change.

Tech M&A Watch: AI Infrastructure and Security Drive New Acquisitions Tech M&A Watch: AI Infrastructure and Security Drive New Acquisitions Reviewed by Erwin Castro on Thursday, September 24, 2026 Rating: 5
CRM + marketing automation + payments in one integrated platform. Helps small businesses streamline sales and automate the follow-up work that falls through the cracks. Get Keap