Fortinet AI Data Center Security Demand Is Rising, but Neocloud Scale Is the Real Test
Fortinet says AI data center security demand has moved beyond pilot projects, supported by an eight-figure neocloud contract and several infrastructure wins. The shift gives its firewall business a new growth engine beyond the familiar enterprise replacement cycle.
The numbers strengthen that case. Fortinet reported second-quarter revenue of $2.05 billion, up 26% from the prior year. Product revenue rose 52% to $773 million, while billings increased 33% to $2.37 billion.
Yet the central question is not whether AI infrastructure needs security. It clearly does. The harder question is whether neocloud expansion can create a repeatable market before spending concentrates among a few large operators.
That distinction places Fortinet against Palo Alto Networks, Cisco, Check Point, and cloud-native security providers. Each vendor wants to control the security layer surrounding expensive AI systems.
Fortinet enters that contest with custom processors, established firewall deployments, and an integrated operating system. Its argument is straightforward: AI networks need deeper inspection without sacrificing the speed that keeps costly GPUs productive.
The opportunity remains young, however. One large deal proves that a customer will buy. It does not prove that the wider neocloud market will standardize around Fortinet.
Fortinet AI Data Center Security Has Become a Revenue Story
Fortinet’s AI narrative now includes measurable contracts and financial momentum, not only product positioning.
On July 29, 2026, Fortinet reported results for the quarter ending June 30. Its quarterly results exceeded the high end of company guidance for revenue and profitability.
Product revenue supplied the clearest signal. Its 52% increase outpaced service revenue, which grew 14% to $1.27 billion. Fortinet attributed the product strength to unit growth and customers choosing higher-performing FortiGate models.
That mix matters because AI data centers need physical infrastructure. Virtual controls remain important, but high-volume network inspection often requires specialized hardware placed close to the workload.
Fortinet also disclosed an eight-figure contract with an unnamed neocloud provider. A neocloud is a specialized cloud operator that supplies hosted GPU infrastructure for AI training and inference.
The provider selected Fortinet to secure multiple AI data centers, according to the company. The contract followed a seven-figure deal with the same customer during the first quarter.
Fortinet said the buyer prioritized price-to-performance and scalable, high-throughput security. The customer wanted to add computing capacity while maintaining consistent policies and operational control.
The progression from a seven-figure deployment to an eight-figure expansion is significant. It suggests that an initial installation passed enough internal tests to support a larger commitment.
Management also said it saw other AI data center wins during the quarter. Those deals came from customers expanding AI infrastructure, though Fortinet did not disclose their combined value.
The neocloud contract is still only one named category of customer. Fortinet withheld the operator’s identity, deployment size, contract duration, and revenue-recognition schedule.
Those omissions limit outside analysis. An eight-figure agreement can represent hardware, subscriptions, support, or a combination delivered across several periods.
Fortinet’s broader results provide more context. Secure Networking billings increased 34%, supported by demand across FortiGate deployments, operational technology, campus networks, and AI data centers.
Operational technology billings rose more than 55%. Unified SASE billings grew 35%, while AI-driven Security Operations billings increased 25%.
SASE, or secure access service edge, combines network access and security functions through a distributed architecture. Fortinet uses the term “SASE Firewall” for deployments that join local enforcement with cloud-delivered controls.
The company said FortiSASE adoption reached 19% among its large-enterprise installed base. FortiSASE billings more than doubled, benefiting from expansions and competitive replacements.
These figures show why Fortinet’s AI story cannot be separated from its wider portfolio. AI workloads create traffic, but the company sells the surrounding network, access, segmentation, and operations layers.
Fortinet also raised its full-year revenue outlook. It now expects revenue between $8.02 billion and $8.18 billion, representing 19% growth at the midpoint.
Management expects third-quarter revenue between $2.01 billion and $2.10 billion. Its billings forecast ranges from $2.25 billion to $2.35 billion.
The evidence supports a real demand increase. It does not establish how much of that increase comes directly from neoclouds.
Firewall refreshes, higher average selling prices, operational technology projects, and SASE adoption also contributed. Investors and buyers should avoid assigning every percentage point to AI infrastructure.
That ambiguity creates the article’s central tension. Fortinet neocloud demand is visible, but its scale remains embedded inside a much broader network-security cycle.
Why Neocloud Growth Creates More AI Firewall Demand
Every new AI cluster creates a security problem shaped by traffic volume, latency, segmentation, and the high cost of idle computing.
Neocloud operators compete by providing access to accelerators without requiring customers to build private facilities. Their environments connect GPUs, storage, management systems, customer workloads, and external services.
Much of that communication travels east to west. East-west traffic moves between systems inside a data center, rather than entering or leaving through its perimeter.
AI clusters intensify this pattern. Training and inference systems exchange large datasets, model parameters, prompts, outputs, and control messages across dense internal networks.
Security teams need to separate customers, administrative systems, data pipelines, and model-serving environments. They must also inspect traffic without creating a bottleneck around valuable accelerators.
Traditional perimeter controls cannot handle the entire task. An attacker who gains internal access can move laterally unless the operator divides the environment into enforceable security zones.
Zero-trust segmentation addresses that risk by continuously restricting communication between systems. Access depends on identity, workload context, and policy instead of network location alone.
Encryption creates another tradeoff. It protects data in transit, but it can obscure malicious activity from security tools.
Decrypting and inspecting traffic consumes computing resources. When inspection throughput falls behind network throughput, operators must reduce visibility or accept slower application performance.
Fortinet argues that its custom FortiASIC processors reduce this compromise. These application-specific integrated circuits accelerate networking and security functions inside FortiGate appliances.
That architecture is the foundation of Fortinet AI data center security. The company wants its firewalls to inspect high-volume traffic while preserving predictable latency and energy use.
Its May 2026 FortiGate expansion added the FortiGate 3500G and 400G. Both use Fortinet processors and the FortiOS operating system.
The 3500G targets dense data center environments. Fortinet lists 400-gigabit connectivity, 595 gigabits per second of firewall throughput, and 105 gigabits per second of threat protection.
Those specifications come from Fortinet’s testing and published competitor comparisons. Buyers should validate them using their own traffic, policies, encryption settings, and logging requirements.
The 400G targets enterprise edges and distributed environments. Fortinet positions it as an upgrade path for organizations handling more encrypted traffic and AI application use.
FortiOS 8.0 also expands inspection for Model Context Protocol and agent-to-agent traffic. Model Context Protocol gives AI applications a standard way to connect with tools and information sources.
That traffic introduces distinct questions. Security teams need to know which agent requested an action, which data it accessed, and whether the response crossed a policy boundary.
AI firewall demand therefore extends beyond GPU clusters. Enterprises using hosted models also need visibility into employee activity, application programming interfaces, autonomous agents, and outbound data transfers.
Fortinet’s Gen AI dashboard illustrates this operational layer. It can show connections to AI providers, files uploaded, large outbound transfers, and spikes in AI application requests.
These controls address shadow AI, meaning AI services used without formal organizational approval. Shadow AI can expose confidential data even when the underlying model service remains secure.
The company’s product strategy connects these use cases. FortiGate provides enforcement, FortiGuard supplies threat intelligence, and FortiOS manages policies across different deployment locations.
Fortinet says this shared architecture reduces the number of separate tools that teams must operate. It also claims that custom processors improve performance per unit of energy.
The mechanism is credible, but results remain workload-dependent. A marketing specification cannot reproduce an operator’s mix of packet sizes, encrypted sessions, security services, and failure conditions.
Neocloud operators also have strong reasons to customize infrastructure. Their business models depend on utilization and unit economics, which can make proprietary software or specialized network designs attractive.
Fortinet succeeds if standardized security appliances offer enough performance and simpler operations. It loses leverage if large operators build more enforcement directly into their cloud platforms.
This is why the eight-figure expansion deserves attention. It indicates that at least one specialized provider chose an external security platform while scaling its own infrastructure.
The next test is repetition. Fortinet needs several operators to make similar decisions across production clusters, not just one customer expanding a preferred design.
Neocloud Economics Favor Speed, While Security Demands Control
The main contest is between rapid infrastructure expansion and the operational discipline required to secure shared AI systems.
Neoclouds build capacity under intense pressure. Customers want access to scarce accelerators, while operators must bring facilities online before hardware loses economic value.
Security controls can slow deployment when they require complex integration or extensive manual tuning. Weak controls create a different cost through outages, breaches, customer loss, and compliance failures.
Fortinet is selling a way around that conflict. Its pitch combines local enforcement, centralized policy, specialized processors, and security services within one platform.
Its prepared remarks describe AI as a driver of infrastructure modernization. Customers need to secure models, datasets, applications, and growing internal traffic.
Fortinet also says shared telemetry can improve visibility while reducing operational overhead. Shared telemetry collects security signals from several controls into a common system.
That model appeals to operators that cannot staff every function with a separate specialist. A common platform can reduce policy differences across facilities and deployment phases.
However, consolidation also increases dependency on one vendor. A software defect, management failure, or exposed administrative system can affect several layers simultaneously.
The company’s approach also reaches beyond conventional network boundaries. Its Secure AI Data Center framework covers segmentation, application security, model traffic, data protection, and incident response.
Fortinet introduced that framework in November 2025 with the FortiGate 3800G. The security framework includes 400-gigabit Ethernet and protection for GPU clusters.
Fortinet claims the design reduces average power consumption by 69% compared with traditional approaches. That figure comes from the company and should not be treated as universal.
The comparison relies on selected products, published specifications, and defined workloads. Actual power use depends on enabled services, utilization, redundancy, cooling, and network architecture.
Energy still matters because AI facilities already face demanding power requirements. Security overhead that raises consumption also raises operating costs and complicates capacity planning.
Performance claims therefore serve a commercial purpose. Fortinet wants buyers to view security processing as infrastructure acceleration rather than a tax on useful computing.
Palo Alto Networks makes a competing argument around application visibility, threat prevention, software firewalls, and cloud security. Cisco can connect security decisions with an extensive networking installed base.
Check Point emphasizes consolidated prevention and management. Cloud-native vendors can integrate controls directly into workload orchestration, identity systems, and developer workflows.
These competitors pressure Fortinet from different directions. Appliance vendors challenge its throughput and security efficacy, while software providers challenge the need for dedicated hardware.
Fortinet’s answer is hybrid deployment. The same operating system can run across physical appliances, virtual systems, cloud environments, and SASE services.
That consistency can help customers manage workloads moving between private facilities and hosted infrastructure. It can also reduce retraining when an enterprise already uses FortiGate products.
Existing relationships matter because security procurement is rarely a blank-sheet decision. Buyers often extend familiar platforms when the architecture and risk profile permit it.
Fortinet’s installed base creates a channel into enterprise AI projects. A company already using FortiGate can add segmentation, secure branches, or control AI traffic without changing every management process.
Neoclouds present a different opportunity. Many are younger companies without decades of inherited network design, giving vendors a chance to become part of the standard blueprint.
Winning those designs can produce later expansion. A provider that repeats one architecture across regions might purchase more appliances and attached subscriptions as capacity grows.
That model also concentrates risk. If a few large neocloud operators dominate the market, their procurement decisions can produce uneven results for suppliers.
Large customers negotiate aggressively and can shift designs. They may also delay deployments when financing, electricity, accelerators, or customer commitments become constrained.
Fortinet’s disclosed contract shows demand at one operator. It does not reveal whether the customer has durable utilization or whether the new facilities will fill quickly.
The company must therefore balance two messages. AI creates a structural need for security, but neocloud purchasing can remain volatile and project-based.
Enterprise AI use offers a broader cushion. More applications create additional traffic, data-loss concerns, identity risks, and pressure to inspect encrypted connections.
Fortinet does not need every enterprise to own a GPU cluster. It can benefit when customers connect to hosted models, deploy internal agents, or segment sensitive data from AI services.
That broader demand makes the opportunity more durable than neocloud construction alone. It also makes attribution harder because the same firewall can serve many business applications.
What Fortinet’s Numbers Still Do Not Prove
Strong quarterly growth supports Fortinet’s thesis, but it cannot yet separate AI demand from refresh cycles, pricing, and wider security consolidation.
Fortinet reported higher unit volumes and higher average selling prices during the second quarter. Customers shifted toward models with greater performance, according to management.
That pattern fits AI infrastructure requirements. It also fits ordinary upgrades from older firewalls that can no longer handle encrypted traffic or expanded networks.
Fortinet has discussed a multiyear replacement opportunity linked to products approaching their end-of-service dates. Those replacements can lift product revenue even without a neocloud boom.
Operational technology also contributed materially. OT billings rose more than 55%, reflecting demand in industrial environments that have different purchasing cycles from AI data centers.
Unified SASE added another source of acceleration. Its billings increased 35%, and FortiSASE expansions helped the product more than double its billings.
These overlapping drivers are positive for Fortinet’s business. They make it difficult to calculate a clean measure of Fortinet neocloud demand.
Management did not disclose AI-related bookings as a separate line. It also did not provide a neocloud customer count, renewal rate, backlog, or average contract size.
The absence of that detail is not unusual for an emerging segment. It means readers should treat the eight-figure agreement as evidence, not a market forecast.
Services growth deserves attention as well. Product revenue rose 52%, but service revenue increased 14%.
Hardware usually creates future subscription and support opportunities. If AI deployments become durable, attached services should eventually contribute a larger recurring stream.
Fortinet said service billings grew 26% and deferred revenue increased 17%. Management also believes first-quarter service growth marked a low point.
Those figures support improving momentum. Future quarters must show whether higher product sales convert into sustained service revenue rather than temporary appliance demand.
Security effectiveness presents another uncertainty. Throughput has little value if policies miss attacks, create false positives, or fail under realistic encrypted traffic.
Independent testing helps, but buyers must examine test sponsorship and configuration. Competing vendors often publish different results using different traffic profiles and enabled features.
A useful evaluation should include full inspection, logging, high availability, policy updates, failure recovery, and representative application behavior. Peak firewall throughput alone is insufficient.
AI-specific threats also extend above the network layer. Prompt injection manipulates a model through crafted instructions, while model poisoning corrupts training or adaptation data.
Network controls can observe and restrict relevant traffic. They cannot independently guarantee model integrity, safe outputs, correct authorization, or secure application logic.
The AI risk framework from the National Institute of Standards and Technology encourages organizations to manage AI risks across governance, measurement, and operations.
That wider framework highlights a limit of infrastructure-led narratives. Firewalls form one control layer, not a complete AI governance system.
Neoclouds also operate shared infrastructure. Isolation failures can involve compute scheduling, storage, identities, management interfaces, or software dependencies beyond the network.
Fortinet can reduce exposure through segmentation, inspection, and policy enforcement. It cannot remove every vulnerability across an operator’s hardware and software supply chain.
Product security matters too. A network appliance occupies a privileged position and becomes a valuable target.
Customers should evaluate vulnerability response, patching speed, administrative access, logging integrity, and recovery procedures alongside performance. Vendor consolidation increases the importance of those controls.
Sovereignty adds another complication. Organizations increasingly want data processing and security enforcement within defined jurisdictions.
Fortinet supports local, cloud, hybrid, and sovereign SASE deployments. This flexibility can help customers meet latency and regulatory requirements.
However, data location alone does not establish compliance. Buyers still need evidence covering access controls, subprocessors, encryption keys, retention, and incident reporting.
The same caution applies to AI inspection features. Visibility into prompts and model responses can support security, but it can also expose sensitive content to additional systems.
Organizations need clear retention and access policies for those records. Security telemetry should not become an uncontrolled copy of confidential AI interactions.
The strongest interpretation of the quarter is therefore narrow. Fortinet has converted AI infrastructure needs into meaningful contracts and higher-capacity product demand.
The weaker interpretation is still unproven. Current disclosures do not show that neoclouds have become a large, predictable, independently measured revenue category.
That gap does not invalidate management’s position. It defines the evidence investors and enterprise buyers should request next.
Three Signals Will Show Whether the Demand Endures
Contract repetition, attached service growth, and production performance will determine whether this becomes a durable market or a concentrated buildout cycle.
The first signal is another disclosed neocloud expansion. Fortinet should show that the eight-figure customer is part of a wider pattern across specialized GPU providers.
Several wins with different operators would strengthen the market thesis. A single customer growing again would support execution, but it would leave concentration concerns unresolved.
The most useful disclosure would include customer count, approximate deployment phases, and whether contracts cover hardware, software, or attached services. Fortinet need not identify every buyer.
A slowdown in new operators would weaken the argument. It would suggest that demand depends on a small group of builders or one unusually successful relationship.
The second signal is conversion from product sales into recurring services. Fortinet’s product momentum should produce subscriptions, support, threat intelligence, and security-operations revenue over time.
Investors should compare service revenue growth, service billings, and deferred revenue with hardware growth. A narrowing gap would indicate that deployments are becoming operational commitments.
Continued strength in FortiSASE and AI-driven Security Operations would also matter. Those products show whether customers adopt Fortinet beyond the initial firewall purchase.
Weak service conversion would not erase the hardware opportunity. It would make revenue more dependent on construction schedules and periodic capacity additions.
The third signal is credible production validation. Buyers need evidence that Fortinet can inspect realistic AI traffic without unacceptable latency, power use, or operational complexity.
Customer case studies should document enabled security services, encrypted traffic, availability requirements, and measured outcomes. Generic maximum-throughput claims provide less decision value.
Competitive responses will sharpen that evidence. Palo Alto Networks, Cisco, Check Point, and cloud security providers will publish their own designs and performance comparisons.
That pressure benefits buyers. It forces vendors to explain which layer they secure, which threats they detect, and where their performance claims stop applying.
Fortinet has a plausible advantage when customers value custom processors and one operating system across physical and virtual deployments. Its disadvantage appears when buyers prefer controls embedded into cloud software and workload identity.
The market will not select one architecture for every environment. Large AI operators can combine high-throughput appliances, virtual firewalls, identity controls, application defenses, and internal tooling.
Fortinet’s goal is to become the common enforcement layer across that mix. The eight-figure neocloud win shows that this outcome is achievable in at least one expanding environment.
Enterprise buyers should use the moment to revisit their own assumptions. AI security is not limited to blocking access to public chatbots.
Teams should map model traffic, internal data movement, agent permissions, encryption, administrative paths, and third-party infrastructure. They should then test controls under production conditions.
Knowledge workers also have a role. Unsanctioned AI activity often begins with ordinary attempts to summarize documents, analyze files, or automate repetitive work.
Clear policies and approved systems can reduce that exposure. Network enforcement works best when users understand which tools are permitted and how sensitive information should be handled.
Fortinet AI data center security has become a credible commercial story, backed by an eight-figure expansion and strong quarterly growth. It has not yet become a transparent standalone market.
The next few quarters should reveal whether other neoclouds adopt similar designs, whether services follow hardware, and whether production testing supports Fortinet’s performance claims.
For security leaders, the immediate action is practical: identify where AI traffic flows, test inspection under full load, and demand workload-specific evidence from every vendor.



