Fortinet Buys Virtue AI to Put Controls Around Agent Actions
Fortinet is adding runtime monitoring, agent testing and tool-call controls to its AI-security lineup. The critical test is whether those pieces become manageable controls inside the company’s broader Security Fabric.
Listen to this story
The audio brief
Story brief
3 key pointsFortinet’s acquisition of Virtue AI adds continuous testing, runtime monitoring and enforcement for enterprise agents to its Security for AI strategy. Virtue AI is positioned alongside FortiAIGate, extending protection from model-level threats to agent permissions, MCP tools, API calls and business actions. Its stated capabilities include red-teaming across 50+ sandboxed environments and 14 high-stakes domains, plus...
- 01
Fortinet says Virtue AI can discover unsanctioned agents, scan source code and MCP tools, monitor behavior, and block risky calls before execution.
- 02
Automated validation is designed to rerun after model, prompt, data-source, tool, permission or policy changes—not just before launch.
- 03
Financial terms were undisclosed; Fortinet called the consideration immaterial to its business.
Fortinet has acquired Virtue AI, bringing AI runtime protection, automated validation and security technology for autonomous AI systems into its portfolio. Fortinet says it will add the technology to its AI-Native Security Fabric to protect AI models, applications and agentic systems across their lifecycle.
The purchase extends an existing Fortinet product line rather than replacing it. Fortinet says FortiAIGate protects large language models from prompt injection, data leakage, model poisoning and excessive resource consumption. Virtue AI is intended to complement that product with protection for models, applications and agentic systems during development and runtime.
The control problem is the agent’s reach
The security question changes when an AI system can retrieve information, call APIs, trigger workflows and interact with business applications. An industry analyst described the resulting task as governing an agent’s permissions, connected tools and permitted decisions—not only filtering its prompts or model outputs.
Fortinet describes the relevant attack surface as including prompts, models, agents, Model Context Protocol tools, API calls and AI infrastructure. It says Virtue AI can discover unsanctioned AI applications and agents, scan MCP tools and source code for risks, monitor agent behavior, and block malicious tool calls before execution.
Why one prelaunch test is not enough
An agent’s risk profile can change when its model, prompts, data sources, tools, permissions or business role changes. That makes periodic approval a limited safeguard: the same workflow can gain a new connector, broader access or changed model behavior after it is deployed.
Fortinet says Virtue AI’s continuous validation identifies new risks after model updates and policy fine-tuning, and generates audit-ready evidence for security and compliance reviews. The analyst’s recommended operating model adds runtime monitoring and records that connect an agent’s prompts, decisions, tool calls, identity and outcomes.
What Virtue AI adds, according to Fortinet
- Automated red-teaming of autonomous agents across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks.
- Governance and visibility tools for agents and AI tools, including discovery, code and MCP scanning, behavior monitoring, and tool-call blocking.
- Real-time guardrails for text, images, video, audio and AI-generated code.
The purchase settles ownership, not execution
Financial terms were not disclosed; Fortinet said the consideration was immaterial to its business. The company places the acquisition within its Security for AI strategy, alongside FortiAIGate, coordinated enforcement and FortiGuard Labs threat intelligence.
Fortinet also cited Gartner research forecasting that the market for securing AI ecosystems and agents will rise from $2.8 billion in 2026 to $16.4 billion by 2030. That forecast is not a Fortinet revenue projection, but it shows the market opportunity the company is pursuing.
Virtue AI gives Fortinet a stated set of testing, monitoring and enforcement capabilities for enterprise agents. The open question is product execution: Fortinet still must show that the technology fits into the Security Fabric without unnecessary operational complexity and performs across multivendor environments, the analyst said.
Sources
- finance.yahoo.comFortinet Advances Continuous AI Protection with the Acquisition of Virtue AI
- techafricanews.comFortinet Acquires Virtue AI to Strengthen Agentic AI Security - TechAfrica News
- citybiz.coFortinet Acquires Virtue AI to Expand Security for Agentic AI Systems
- siliconangle.comFortinet’s Virtue AI acquisition rebalances the agentic AI security equation - SiliconANGLE
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.