Fortinet Buys Virtue AI to Put Controls Around Agent Actions

Fortinet is adding runtime monitoring, agent testing and tool-call controls to its AI-security lineup. The critical test is whether those pieces become manageable controls inside the company’s broader Security Fabric.

By 3 min read
Fortinet Buys Virtue AI to Put Controls Around Agent Actions
Fortinet Buys Virtue AI to Put Controls Around Agent Actions

Listen to this story

The audio brief

About 1:36
0:001:36
Read transcript
Fortinet has acquired Virtue AI, adding controls designed to watch and test autonomous AI agents while they are running—not just before launch. The deal extends Fortinet’s existing AI-security lineup. FortiAIGate focuses on threats to large language models, including prompt injection, data leakage, model poisoning and excessive resource use. Virtue AI is aimed at what happens after a model can retrieve information, call APIs, trigger workflows and act inside business systems. Fortinet says the technology can discover unsanctioned agents, scan source code and Model Context Protocol tools, monitor behavior, and block risky tool calls before they execute. Its automated validation can rerun when a model, prompt, data source, tool, permission or policy changes. That matters because an agent approved at launch can become materially riskier after it gains a new connector or broader access. The company also cites automated red-teaming across more than 50 sandboxed environments and 14 high-stakes domains, plus real-time guardrails for text, images, video, audio and generated code. Financial terms were not disclosed; Fortinet called the consideration immaterial to its business. Gartner forecasts the market for securing AI ecosystems and agents will grow from 2.8 billion dollars in 2026 to 16.4 billion by 2030. That is a market estimate, not a Fortinet revenue forecast. The real test is execution: whether Virtue AI’s monitoring and enforcement become manageable controls inside Fortinet’s broader Security Fabric, including across multivendor environments.

Story brief

3 key points

Fortinet’s acquisition of Virtue AI adds continuous testing, runtime monitoring and enforcement for enterprise agents to its Security for AI strategy. Virtue AI is positioned alongside FortiAIGate, extending protection from model-level threats to agent permissions, MCP tools, API calls and business actions. Its stated capabilities include red-teaming across 50+ sandboxed environments and 14 high-stakes domains, plus...

  1. 01

    Fortinet says Virtue AI can discover unsanctioned agents, scan source code and MCP tools, monitor behavior, and block risky calls before execution.

  2. 02

    Automated validation is designed to rerun after model, prompt, data-source, tool, permission or policy changes—not just before launch.

  3. 03

    Financial terms were undisclosed; Fortinet called the consideration immaterial to its business.

Fortinet has acquired Virtue AI, bringing AI runtime protection, automated validation and security technology for autonomous AI systems into its portfolio. Fortinet says it will add the technology to its AI-Native Security Fabric to protect AI models, applications and agentic systems across their lifecycle.

The purchase extends an existing Fortinet product line rather than replacing it. Fortinet says FortiAIGate protects large language models from prompt injection, data leakage, model poisoning and excessive resource consumption. Virtue AI is intended to complement that product with protection for models, applications and agentic systems during development and runtime.

The control problem is the agent’s reach

The security question changes when an AI system can retrieve information, call APIs, trigger workflows and interact with business applications. An industry analyst described the resulting task as governing an agent’s permissions, connected tools and permitted decisions—not only filtering its prompts or model outputs.

Fortinet describes the relevant attack surface as including prompts, models, agents, Model Context Protocol tools, API calls and AI infrastructure. It says Virtue AI can discover unsanctioned AI applications and agents, scan MCP tools and source code for risks, monitor agent behavior, and block malicious tool calls before execution.

Why one prelaunch test is not enough

An agent’s risk profile can change when its model, prompts, data sources, tools, permissions or business role changes. That makes periodic approval a limited safeguard: the same workflow can gain a new connector, broader access or changed model behavior after it is deployed.

Fortinet says Virtue AI’s continuous validation identifies new risks after model updates and policy fine-tuning, and generates audit-ready evidence for security and compliance reviews. The analyst’s recommended operating model adds runtime monitoring and records that connect an agent’s prompts, decisions, tool calls, identity and outcomes.

What Virtue AI adds, according to Fortinet

  • Automated red-teaming of autonomous agents across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks.
  • Governance and visibility tools for agents and AI tools, including discovery, code and MCP scanning, behavior monitoring, and tool-call blocking.
  • Real-time guardrails for text, images, video, audio and AI-generated code.

The purchase settles ownership, not execution

Financial terms were not disclosed; Fortinet said the consideration was immaterial to its business. The company places the acquisition within its Security for AI strategy, alongside FortiAIGate, coordinated enforcement and FortiGuard Labs threat intelligence.

Fortinet also cited Gartner research forecasting that the market for securing AI ecosystems and agents will rise from $2.8 billion in 2026 to $16.4 billion by 2030. That forecast is not a Fortinet revenue projection, but it shows the market opportunity the company is pursuing.

Virtue AI gives Fortinet a stated set of testing, monitoring and enforcement capabilities for enterprise agents. The open question is product execution: Fortinet still must show that the technology fits into the Security Fabric without unnecessary operational complexity and performs across multivendor environments, the analyst said.

Sources

  1. finance.yahoo.comFortinet Advances Continuous AI Protection with the Acquisition of Virtue AI
  2. techafricanews.comFortinet Acquires Virtue AI to Strengthen Agentic AI Security - TechAfrica News
  3. citybiz.coFortinet Acquires Virtue AI to Expand Security for Agentic AI Systems
  4. siliconangle.comFortinet’s Virtue AI acquisition rebalances the agentic AI security equation - SiliconANGLE

Loading discussion...