Tech M&A Watch: AI Infrastructure and Security Drive New Acquisitions
Watch Tech Series · Tech M&A Watch | September 24, 2026
Daily M&A intelligence covering technology acquisitions, strategic deals, AI infrastructure, cybersecurity, cloud platforms, enterprise software, and the capabilities changing hands across the technology market.
Technology M&A is moving beyond conventional software consolidation and deeper into the infrastructure and security layers required to operate AI at scale. Nutanix’s acquisition of AI orchestration company Ryax Technologies and Upwind’s acquisition of AI-security startup Aegis illustrate a common strategic objective: gaining control over the software that makes AI systems more efficient, governable, and secure.
The shared deal signal is strategic capability. Nutanix is adding AI-aware compute orchestration to improve GPU use and workload placement across hybrid environments. Upwind is adding AI-security research and product capabilities as models, agents, and autonomous workflows become connected to production systems. In both cases, the buyer is acquiring a control layer around AI rather than simply buying another AI application.
M&A Theme
Companies are increasingly acquiring the layers required to make AI operational: infrastructure optimization, orchestration, identity, security, software tooling, deployment and management.
Lead Deal
AI Infrastructure M&A
Nutanix Acquires Ryax Technologies to Add AI Compute Orchestration
Buyer: Nutanix · Target: Ryax Technologies
Nutanix acquired France-based Ryax Technologies, an AI-driven compute orchestration and management company. Financial terms were not disclosed. Nutanix said it plans to integrate Ryax’s GPU-utilization and smart-scheduling capabilities into future releases of Nutanix Kubernetes Platform (NKP) and Nutanix Enterprise AI (NAI).
Ryax adds technology around intelligent resource optimization, AI-aware workload scheduling and infrastructure management. Nutanix positions the acquisition as part of its strategy to help enterprises build, run and govern agentic AI across private data centers, hyperscalers, neoclouds and high-performance computing environments.
The strategic asset is not another AI model or end-user application. Nutanix is acquiring part of the infrastructure-management layer that sits between AI workloads and underlying compute. As enterprises distribute workloads across private infrastructure, public cloud, GPU clouds, and HPC systems, intelligent placement and scheduling can become a differentiating capability.
| Deal Intelligence Field | Nutanix / Ryax Assessment |
|---|---|
| Buyer | Nutanix, a hybrid multicloud and enterprise infrastructure software provider. |
| Target | Ryax Technologies, a France-based developer of AI-driven compute orchestration and management software. |
| Capability | GPU utilization, resource optimization, smart scheduling, and AI-aware workload placement. |
| Integration target | Future versions of Nutanix Kubernetes Platform and Nutanix Enterprise AI. |
| Strategic motive | Improve the efficiency, management and governance of enterprise AI workloads across hybrid infrastructure. |
| Transaction economics | Financial terms were not disclosed. Nutanix said the acquisition is not expected to be material to its financial results. [71] |
What the deal means: Nutanix is buying AI infrastructure control software. The commercial objective is to help enterprises extract more useful work from expensive and increasingly distributed compute capacity.
Why GPU Utilization Has Become an M&A Issue
AI Infrastructure Economics
Software That Improves AI Capacity Efficiency Is Becoming Strategically Valuable
AI infrastructure is expensive, and expensive infrastructure is valuable only when it is productively utilized. GPU capacity can be underused when workloads are oversized, poorly scheduled, isolated in separate environments, delayed by data or dependency constraints, or deployed without sufficient visibility into actual resource consumption.
Ryax’s platform is designed to improve this operating model through GPU and CPU optimization, AI-aware workload scheduling, automated resource management and placement decisions across hybrid environments. Nutanix said the technology will help customers optimize GPU utilization and streamline AI deployments.
The broader M&A implication is that compute orchestration is becoming a strategic software category. As more enterprises operate AI across private data centers, hyperscalers, neoclouds, edge sites, and HPC environments, the ability to determine where a workload should run can affect performance, availability, cost, data governance, and capacity utilization.
| AI Infrastructure Problem | Orchestration Objective |
|---|---|
| Idle or underused GPUs | Increase utilization through scheduling, workload consolidation, and resource right-sizing. |
| Variable workload demand | Allocate capacity dynamically between training, inference, experimentation, and enterprise workloads. |
| Hybrid infrastructure complexity | Determine where workloads should run across on-premises infrastructure, public cloud, neocloud and HPC resources. |
| Cost pressure | Match capacity, model choice and workload-placement decisions with business value and cost constraints. |
| Operational resilience | Automate recovery and resource reallocation when capacity constraints, workload failures, or infrastructure issues occur. |
M&A signal: As AI compute becomes more expensive, software that improves utilization can become as strategically important as additional hardware capacity.
AI Security M&A
AI Security Deal
Upwind Acquires Aegis and Launches AI Security Labs
Buyer: Upwind · Target: Aegis
Cloud-security company Upwind acquired Aegis, an Israeli AI-security startup that had been operating in stealth. Upwind also launched Upwind AI Security Labs, bringing Aegis co-founders Omri Limor and Saar Ankonina into the company to lead the new research and engineering operation.
The new lab will focus on emerging AI security threats, including AI agents, agent skills and plugins, AI-generated attacks, attack detection, security research and defensive capabilities for AI environments. Upwind describes the initiative as a response to the increasingly connected and autonomous nature of AI systems.
The companies did not publicly disclose financial terms. Axios reported that the all-equity transaction was valued between $25 million and $50 million. That range should be treated as reported, rather than as confirmed consideration disclosed by the parties.
| Deal Intelligence Field | Upwind / Aegis Assessment |
|---|---|
| Buyer | Upwind, a cloud security company. |
| Target | Aegis, an Israeli AI-security startup focused on threats emerging from AI infrastructure and AI agents. |
| Capability | AI security research, agent security, threat detection, scanning, and defensive tools for AI environments. |
| Talent component | Aegis co-founders Omri Limor and Saar Ankonina will lead Upwind AI Security Labs. |
| Strategic motive | Extend cloud security into the emerging attack surface created by AI agents, autonomous workflows and AI-generated attacks. |
| Transaction economics | Terms were not disclosed by the companies. Axios reported an all-equity valuation range of $25 million to $50 million. |
What the deal means: Upwind is acquiring both AI-security capability and specialized talent, then giving the combined team a distinct organizational mandate through AI Security Labs.
The AI Security M&A Layer
Security Platform Expansion
Security Buyers Are Acquiring AI-Specific Capabilities, Not Only Adding AI Features
The Aegis transaction reflects a broader change in cybersecurity. As AI systems become connected to tools, APIs, identities, enterprise information, cloud environments, and production workflows, security teams need to protect more than the model itself. They need to govern the systems, permissions, data flows, and automated actions surrounding the model.
This creates new M&A categories around AI agents, machine identities, non-human access, agent-to-agent interactions, AI workload monitoring, model security, AI-generated attacks, prompt and tool controls, data protection and AI-specific threat research.
The strategic signal is that cybersecurity platforms may need dedicated AI security capabilities rather than treating AI as only another feature inside an existing security product. Upwind’s AI Security Labs provides an example of a buyer using an acquisition to create a specialized research and product organization around this emerging threat category.
| AI Security Layer | M&A Rationale |
|---|---|
| Agent security | Controls for autonomous systems that use tools, access enterprise resources, and perform actions. |
| Machine identity | Visibility and governance for service accounts, APIs, workloads, devices and AI agents. |
| AI attack detection | Research and controls for attacks created, accelerated, or directed by AI systems. |
| Model and workload security | Protection of AI infrastructure, data, model access, deployment paths and runtime environments. |
| Governance and observability | Monitoring of prompts, tools, permissions, behavior, policies, risk and audit trails across AI workflows. |
The Bigger Pattern: Buying the AI Control Layer
2026 M&A Pattern
Infrastructure, Software and Identity Are Becoming AI Control Points
The Nutanix and Upwind acquisitions fit alongside other 2026 transactions that target layers required to make AI useful in enterprise environments. The common objective is not necessarily to own the model. It is to own a critical capability around AI deployment, identity, software portability, orchestration, or security.
| Acquisition | Buyer | Strategic Capability |
|---|---|---|
| Ryax Technologies | Nutanix | AI compute orchestration, GPU utilization, workload scheduling and hybrid AI management. |
| Aegis | Upwind | AI security research, agent security, AI attack detection, and specialist security talent. |
| Permiso Security | Okta | Threat detection and mitigation across human, non-human, and agentic identities in multi-cloud environments. Okta closed the acquisition on August 26. |
| Modular | Qualcomm | AI-native software infrastructure for generative and agentic AI across data-center and edge environments. Qualcomm completed the acquisition in July; Reuters reported the all-stock deal at nearly $4 billion. |
Okta’s acquisition of Permiso was aimed at identity threat detection and response across human, non-human and agentic identities. The platform is intended to add identity-risk signals, behavioral analytics and detection capabilities to Okta’s identity architecture.
Qualcomm’s acquisition of Modular shows the same control-layer thesis on the infrastructure side. Modular gives Qualcomm AI-native software infrastructure intended to support generative and agentic AI across data-center and edge systems, strengthening Qualcomm’s software foundation beyond the chip itself.
Recurring theme: Companies are acquiring the software, infrastructure, and security layers needed to make AI operational—not only the applications that users see.
From AI Applications to AI Infrastructure
Strategic Market Shift
The Next AI M&A Layer Is Operational Infrastructure
The first major phase of AI dealmaking was often associated with applications, foundation models, and talent. The next strategic layer is increasingly operational: how AI is deployed, connected, governed, secured, observed, optimized, and integrated with enterprise systems.
↓
Orchestration
↓
Security
↓
Identity
↓
Deployment
↓
Management and Governance
A company does not necessarily need to acquire an AI model developer to strengthen its AI position. It may instead acquire the software that improves GPU efficiency, the identity platform that governs agents, the observability tools that monitor AI workflows, the security research team that detects AI attacks, the data platform that supplies enterprise context, or the deployment layer that makes multiple models usable in production.
This changes the M&A environment. A relatively small infrastructure or security target may be strategically important because it fills a gap that blocks a larger platform from delivering enterprise AI at scale.
| AI Operating Layer | Potential Acquisition Target Type |
|---|---|
| Compute efficiency | GPU orchestration, workload scheduling, capacity management, inference optimization, and FinOps software. |
| Security | AI agent protection, threat research, model security, attack detection and AI security posture management. |
| Identity | Machine identity, agent identity, non-human access, secrets management and privileged access controls. |
| Data and context | Data platforms, retrieval systems, AI data governance, connectors, labeling and domain datasets. |
| Deployment and operations | Model gateways, agent runtimes, observability, evaluation systems, workflow platforms and infrastructure automation. |
Build vs Buy
Strategic Acquisition Logic
Why Nutanix and Upwind Bought Rather Than Built
Nutanix could have expanded its AI infrastructure management capabilities entirely through internal product development. Instead, it acquired an existing AI compute orchestration platform and team, accelerating access to GPU utilization and smart-scheduling capabilities intended for NKP and NAI. That decision suggests the technology and specialized expertise were sufficiently mature and strategically useful to justify acquisition.
Upwind could have built a dedicated AI-security research group internally. The Aegis acquisition instead gives it a specialized founding team, a technology base, and an immediate organizational structure for AI Security Labs. The structure indicates that talent and research depth are part of the strategic asset, not simply an adjunct to a product acquisition.
In both cases, buying offers speed. But the deeper rationale is control: Nutanix can embed orchestration into its platform roadmap, while Upwind can shape AI-security research and capabilities inside its cloud-security architecture.
| Build vs. Buy Factor | Nutanix / Ryax | Upwind / Aegis |
|---|---|---|
| Speed | Adds established orchestration capabilities to the AI infrastructure roadmap. | Creates a dedicated AI-security research operation immediately. |
| Technology | GPU utilization, scheduling, placement, and resource optimization. | AI security, attack detection, scanning, and agent-focused security capabilities. |
| Talent | Specialized compute-orchestration engineering and product expertise. | Founders and specialist AI-security researchers who will lead the new lab. |
| Control | Embeds infrastructure management directly into Nutanix AI platform releases. | Brings AI-security research and product direction inside Upwind’s platform strategy. |
| Integration challenge | Translate orchestration technology into a coherent hybrid-cloud customer experience. | Convert research and emerging capabilities into scalable security products and measurable customer outcomes. |
M&A Economics
Deal Economics Watch
Capability Can Matter More Than Headline Purchase Price
The current transactions show why M&A analysis should not depend entirely on disclosed transaction value. Nutanix did not disclose the price for Ryax. Upwind did not disclose terms for Aegis, although Axios reported an all-equity valuation range of $25 million to $50 million. The strategic importance of both deals comes from the capabilities being acquired, the platform integration plans and the market layers they address.
| Transaction | Economics | Primary Strategic Asset |
|---|---|---|
| Nutanix / Ryax | Financial terms undisclosed; Nutanix said the deal is not expected to be material to financial results. | AI compute orchestration, GPU utilization and hybrid workload management. |
| Upwind / Aegis | Terms undisclosed by the parties; Axios reported an all-equity valuation range of $25 million to $50 million. | AI-security technology, specialized research team, and AI Security Labs leadership. |
| Okta / Permiso | Terms were not publicly disclosed by Okta; outside reporting placed the value at just under $200 million. | Identity threat detection across human, non-human, and agentic identities. |
| Qualcomm / Modular | All-stock transaction reported by Reuters at nearly $4 billion; Qualcomm completed the acquisition in July. | AI-native software infrastructure spanning data-center and edge AI environments. |
Reporting standard: Disclosed deal value, reported estimates, and strategic interpretation should remain separate. An undisclosed transaction should be reported as undisclosed even when its commercial rationale is clear.
What This Means for Technology M&A
M&A Themes
The AI Stack Is Becoming a Target for Strategic Consolidation
Several themes are visible across the current deal environment:
| Infrastructure optimization | AI infrastructure companies are acquiring or building software that improves compute utilization, deployment efficiency, and workload placement. |
| AI security | Cybersecurity vendors are acquiring specialized capabilities for AI agents, machine identities, autonomous workflows, and AI-generated attacks. |
| Software infrastructure | Chip companies and enterprise platforms are targeting software layers that can strengthen their AI ecosystems beyond hardware alone. |
| Vertical integration | Technology companies increasingly seek control across multiple layers of the AI stack, from chips and cloud capacity to orchestration, identity and security. |
| Talent acquisition | Specialized AI engineering, infrastructure and security talent remains a strategic asset, particularly when paired with product technology and research capability. |
The CODEW M&A Framework
Tech M&A Watch evaluates significant transactions through eight core questions:
| Buyer | Who is acquiring, and what strategic direction has that company established? |
| Target | What company, team, product, technology, or data asset is changing hands? |
| Capability | What does the target actually add to the buyer’s infrastructure, software, or security stack? |
| Strategic Motive | Why does the buyer need this capability, and why does it matter now? |
| Integration | Where will the technology, team, or product be incorporated inside the buyer? |
| Competitive Impact | Which competitors, customers, partners, or suppliers may be affected? |
| Build vs Buy | Why did the buyer acquire instead of building, licensing, or partnering for the capability? |
| Market Signal | What does the transaction reveal about where technology markets and AI control layers are moving? |
M&A Watchlist
| 1. AI infrastructure | GPU orchestration, capacity management, AI FinOps, workload placement, inference optimization, and hybrid AI operations. |
| 2. AI security | Agent security, AI-generated attack detection, model security, AI posture management and AI security research platforms. |
| 3. Machine identity | Non-human identity, agent identity, API access, privileged access, and secrets-management capabilities. |
| 4. AI observability | Agent tracing, model evaluation, tool-call monitoring, AI cost visibility and policy enforcement. |
| 5. Developer and AI software tools | Model deployment, compilers, inference runtimes, agent development platforms and AI application tooling. |
| 6. Data infrastructure | Training data, retrieval, storage, governance, data pipelines and enterprise AI context layers. |
| 7. Robotics and physical AI | Robot foundation models, edge AI, simulation, autonomy, perception, controls and industrial robotics platforms. |
| 8. Semiconductor software | AI compilers, EDA, system software, networking software and tools that help heterogeneous compute operate efficiently. |
| 9. Strategic buyers | Hyperscalers, semiconductor companies, enterprise software platforms, cybersecurity vendors, infrastructure providers and private-equity firms expanding AI capabilities. |
Related CODEW Coverage
→ AI Infrastructure Watch — Compute Orchestration, GPU Utilization and the Economics of AI Capacity
→ Cybersecurity Watch — AI Agents, Identity and the Expanding Enterprise Attack Surface
→ Cloud Computing Watch — Hybrid AI Infrastructure, Sovereign Cloud and Agent-Native Operations
→ Infrastructure Software Watch — AI Operations, Scheduling, Observability and Infrastructure Automation
→ Semiconductor Watch — AI Software, Accelerators and the System-Level Compute Stack
→ Build vs Buy — Why Technology Companies Buy Critical AI Capabilities
→ M&A Intelligence Hub — Technology Acquisitions, Strategic Deals and Market Consolidation
The Tech M&A Watch Takeaway
The latest transactions show that AI M&A is moving deeper into the operating stack. Nutanix is acquiring technology intended to make AI infrastructure more efficiently managed. Upwind is acquiring AI-security capability as agentic systems and AI-generated attacks create new security requirements. Okta and Qualcomm provide supporting examples of companies buying identity and software infrastructure around AI.
The central M&A question is becoming less about who will buy the next AI application and more about which companies will acquire the infrastructure, software and security capabilities needed to control the AI economy.
Editorial Note
The Newsroom reports which deals were announced. Tech M&A Watch analyzes the capabilities, technologies, talent, infrastructure, customer relationships and market positions changing hands through acquisitions and strategic transactions. This edition examines Nutanix’s acquisition of Ryax Technologies, Upwind’s acquisition of Aegis, and the broader pattern of AI infrastructure, identity, and security acquisitions.
Deal terms and valuation figures may be undisclosed or based on attributed third-party reporting. Nutanix did not disclose financial terms for Ryax. Upwind did not disclose financial terms for Aegis; the reported $25 million to $50 million range is attributed to Axios. Educational content only. Not investment, legal, tax, accounting, merger-arbitrage, cybersecurity, or procurement advice. Product capabilities, transaction status, and market conditions can change.
Reviewed by Erwin Castro
on
Thursday, September 24, 2026
Rating:
