top of page

Fortinet Buys Virtue AI, but Integration Is the Real Security Test

Aug 21
11 min read

Fortinet acquired Virtue AI less than two years after the startup launched, adding specialized defenses for autonomous agents to its expanding security portfolio. The deal appeared across Google News as another cybersecurity acquisition, but the harder story concerns execution. Fortinet must turn a young company’s research-heavy technology into protection that enterprises can deploy, measure, and trust.

The acquisition adds automated red teaming, continuous validation, runtime guardrails, and tools for monitoring autonomous agents. Financial terms were not disclosed. Fortinet reportedly described the consideration as immaterial to its overall business, making this a focused technology acquisition rather than a balance-sheet transformation.

The competitive context matters. Palo Alto Networks already owns Protect AI, while Cisco acquired Robust Intelligence in 2024. These companies are racing to control an emerging security layer between enterprise AI applications, models, data, and external tools. Fortinet is no longer testing whether that market deserves attention. It is buying capabilities to keep pace.

What Fortinet Actually Bought

Fortinet acquired a missing layer between its network controls and the unpredictable behavior of AI agents.

Virtue AI focuses on protecting AI systems during development and operation. Its platform tests models and applications for vulnerabilities, applies runtime policies, and monitors autonomous agents as they call tools or handle information.

Runtime protection means evaluating an AI system while people or software are actively using it. That differs from a one-time assessment performed before deployment. AI behavior can change when a model, system prompt, connected tool, or underlying policy changes.

According to acquisition reporting, Virtue AI’s technology covers text, images, video, audio, and AI-generated code. Its validation system reportedly tests hundreds of attack vectors across more than 1,000 risk categories.

Those numbers describe the breadth of Virtue AI’s internal testing framework. They do not establish detection accuracy, false-positive rates, or performance under each customer’s conditions. Fortinet will need to publish clearer validation data before buyers can compare the system with competing products.

Virtue AI also tests autonomous agents in more than 50 sandboxed environments across 14 high-stakes domains. A sandbox is an isolated environment where potentially unsafe actions can be tested without reaching production systems.

That capability addresses a practical weakness in conventional application security. An agent does not simply return text. It can search records, execute code, update a database, send a message, or trigger an external workflow.

The Model Context Protocol, or MCP, gives AI applications a standard method for connecting with tools and data. Standardization can simplify development, but every connected tool also creates another path for misuse.

Virtue AI’s Guardian Agent technology reportedly inventories agents and tools, scans MCP components and source code, and watches agent behavior. It can also intercept harmful tool calls before execution, according to the company’s product claims.

Fortinet already had products for securing network traffic, cloud workloads, endpoints, and AI interactions. Virtue AI broadens that position by adding security logic designed around model behavior and agent actions.

The company’s FortiAIGate documentation describes a gateway placed between enterprise AI applications and model providers such as OpenAI, Anthropic, and Amazon Bedrock. It inspects interactions and applies controls to prompts, responses, and connected services.

Virtue AI appears designed to make that gateway more adaptive. Instead of relying only on predetermined rules, the combined platform can test an application, observe changes, and enforce policies during operation.

Fortinet has not provided a detailed integration schedule. It has also not specified whether every Virtue AI product will remain available separately. Those details will determine whether customers receive a coherent platform or another collection of consoles.

The acquisition therefore changes Fortinet’s technical inventory immediately, but not necessarily the customer experience. The real product transition begins after the announcement.

Why Agentic AI Security Forced the Deal

Autonomous agents turn model errors into operational security events because they can act on systems instead of only producing questionable answers.

A chatbot might generate an inaccurate response. An agent connected to business systems can combine that error with an authorized action. It might expose a document, alter a record, invoke the wrong tool, or follow a malicious instruction hidden inside retrieved content.

Prompt injection illustrates the problem. An attacker places instructions inside a document, website, email, or database entry that an AI system later reads. If the model treats that material as trusted guidance, the attacker can redirect the agent’s behavior.

Traditional web security controls can detect suspicious requests, malicious files, and known exploit patterns. They do not always understand whether an agent’s tool choice matches the user’s intent or an organization’s policy.

That distinction explains Fortinet’s timing. The company launched FortiAIGate as a control point for enterprise AI traffic. Its Nvidia integration extended the product across data-center and cloud deployments, including autonomous agents.

A gateway can inspect interactions, but autonomous workflows require more than traffic filtering. Security teams also need discovery, adversarial testing, behavioral monitoring, tool governance, and evidence that controls remain effective after changes.

Virtue AI packages those functions around the AI lifecycle. Red teaming probes for failures before deployment. Continuous validation repeats tests when systems change. Runtime guardrails then evaluate real interactions and block selected behavior.

This layered design matters because AI applications rarely remain static. Developers switch model versions, revise prompts, add retrieval sources, connect new tools, and change permissions. Each modification can invalidate an earlier security assessment.

Fortinet CEO Ken Xie framed the acquisition around “continuous AI assurance.” The phrase describes an ongoing process for testing whether an AI system still behaves within defined security and governance boundaries.

Continuous assurance is an attractive goal, but it creates demanding operational requirements. Tests must reflect real applications. Policies must be specific enough to stop harmful actions without blocking legitimate work. Monitoring must also explain why a decision was made.

False positives become especially costly when controls sit inside production workflows. A security layer that blocks routine tool calls can slow employees, interrupt automated processes, and push teams toward unapproved alternatives.

False negatives carry the opposite risk. A guardrail can create confidence while failing against an unfamiliar attack, a new model behavior, or a complex sequence of individually harmless actions.

Fortinet’s advantage is its existing position inside enterprise networks. Its products already observe traffic, identities, endpoints, cloud resources, and security events. That context can help distinguish legitimate agent behavior from suspicious activity.

However, the company must connect those signals without creating excessive complexity. Buyers will expect shared policies, unified incident evidence, and coordinated response across the Fortinet Security Fabric.

The deal is therefore not simply about adding another AI product. Fortinet is trying to combine network context with model-specific testing and runtime controls.

Google News coverage focused on the acquisition itself. Enterprise buyers should focus on whether that combination produces better detection and simpler operations than separate specialist tools.

Fortinet Faces an AI Security Consolidation Race

Fortinet is responding to a market where major security vendors have already acquired startups offering similar lifecycle protection.

Palo Alto Networks completed its acquisition of Protect AI in July 2025. The company said the deal added model scanning, posture management, AI red teaming, runtime protection, and agent security to Prisma AIRS.

Those capabilities overlap with the functions Fortinet is acquiring through Virtue AI. Palo Alto Networks also positioned its platform across development and runtime, giving customers a single framework for discovering AI systems, evaluating risk, and applying protection.

The official Protect AI announcement acknowledged familiar acquisition risks. These include integration challenges, delayed releases, technical defects, and limited market acceptance.

Those warnings apply equally to Fortinet. Buying a capable startup does not guarantee that its software will integrate cleanly with a large vendor’s licensing, support, policy, telemetry, and release systems.

Cisco provides another comparison. It completed its acquisition of Robust Intelligence in 2024 and later made the startup’s technology central to Cisco AI Defense.

Cisco says Robust Intelligence contributed algorithmic red teaming and an AI firewall. Its AI Defense platform is designed to protect model development, application deployment, and production traffic.

Check Point also acquired Lakera, an AI security company known for runtime guardrails and research into prompt injection. Across the sector, established vendors are buying focused teams rather than building every capability internally.

This consolidation reflects customer pressure as much as vendor ambition. Security leaders already manage tools for networks, endpoints, identities, cloud workloads, data loss prevention, and application security. Few want an entirely separate operating model for every AI application.

A large platform vendor can distribute AI security through existing sales channels and management systems. It can also combine AI events with broader threat intelligence, asset inventories, and incident-response workflows.

Specialist companies retain important advantages. They can move quickly, focus on new model behavior, and design products without supporting decades of older architecture. Their researchers often have deeper experience with adversarial machine learning than general cybersecurity teams.

Virtue AI fits that pattern. The startup was founded in 2024 by researchers including Bo Li, Dawn Song, Carlos Guestrin, and Sanmi Koyejo. Its company history highlights work in adversarial machine learning, model evaluation, poisoning attacks, and agent security.

Virtue AI disclosed a combined seed and Series A financing of $30 million in April 2025. The round was led by Lightspeed Venture Partners and Walden Catalyst Ventures, with participation from Prosperity7 and existing investors.

At that time, the company reportedly employed about 20 people and planned significant hiring. It said customers included organizations in finance, healthcare, information technology, and several frontier AI laboratories.

The funding report described Virtue AI as a unified platform spanning red teaming, guardrails, and agent security. That breadth helps explain its appeal to Fortinet.

The acquisition also follows a significant change in Virtue AI’s leadership environment. Axios reported in June 2026 that three founders and other team members were joining Meta Superintelligence Labs.

That earlier movement raises a central integration question. Fortinet may be buying valuable software, intellectual property, customer relationships, and remaining engineering talent. However, the long-term value depends on retaining enough expertise to keep pace with new attacks and models.

Fortinet has not publicly detailed which Virtue AI founders or employees will join the company. It has not explained how the acquisition relates to the reported Meta hires. Buyers should avoid assuming that every person associated with the startup’s research history is transferring with the technology.

The primary contest is now Fortinet versus other consolidated security platforms. Palo Alto Networks, Cisco, and Check Point can all argue that customers should secure AI through a vendor they already use.

Fortinet’s network footprint gives it a credible route into that contest. Its challenge is proving that Virtue AI adds distinctive protection rather than feature parity.

What the Acquisition Does Not Prove

The deal expands Fortinet’s claims and capabilities, but it does not independently prove that the combined platform can secure autonomous agents at enterprise scale.

AI security tests operate against a moving target. A control evaluated with one model version might behave differently after an update. The same application can also expose different risks when developers change prompts, retrieval data, permissions, or tools.

Virtue AI’s catalog of risk categories sounds extensive. Yet category counts do not show whether tests represent each customer’s actual workflow. They also do not reveal how frequently the platform catches new attacks before production incidents occur.

Independent benchmarks for AI security products remain limited. Vendors use different attack libraries, application configurations, definitions, and scoring systems. A larger test count does not automatically indicate better protection.

Runtime guardrails also face a difficult semantic problem. They must interpret intent from incomplete context. A database deletion might be malicious in one workflow and necessary in another.

Organizations can reduce ambiguity through narrow permissions and human approval gates. Those architectural controls remain important even when an AI security platform monitors the agent.

A well-designed deployment should assume that model-level defenses will sometimes fail. Teams should limit each agent’s access, isolate sensitive systems, record tool activity, and require approval for consequential actions.

Fortinet should clarify how Virtue AI works with identity and access controls. Customers need to know whether policies apply to the human user, the agent, the model, the tool, or every layer together.

Data handling presents another question. Automated red teaming may require prompts, outputs, documents, source code, or application details. Regulated organizations will need clear deployment options and retention controls.

Fortinet has promoted support for data sovereignty through FortiAIGate deployments. It should state whether Virtue AI’s validation and monitoring functions can run locally, inside a customer-controlled cloud, or through a vendor service.

Latency also deserves attention. Inline security checks introduce processing steps between an agent’s request and a tool’s response. Fortinet says its broader AI gateway strategy emphasizes performance, but acquisition reporting provides no comparative latency data for Virtue AI.

The company must balance depth of inspection against operational speed. A financial research agent can tolerate a brief review more easily than an automated system managing time-sensitive infrastructure.

Product packaging remains uncertain. Fortinet could integrate Virtue AI into FortiAIGate, sell components separately, or distribute features across multiple products. Each approach changes deployment effort and purchasing decisions.

A single integrated product can reduce tool sprawl. It can also create lock-in if customers cannot use the testing or guardrail functions with competing firewalls, cloud platforms, and security operations tools.

Open interoperability will be an important signal. Enterprise AI environments commonly combine several model providers, orchestration frameworks, databases, clouds, and security vendors.

Fortinet’s documentation already names support for major model services. Virtue AI’s value will increase if it preserves broad framework support and exports findings through standard interfaces.

The acquisition also cannot eliminate basic governance failures. No runtime product can compensate fully for unclear ownership, unrestricted agent permissions, missing inventories, or absent incident procedures.

Security teams need to know which AI systems exist before they can protect them. They must identify the data those systems access, the actions they can perform, and the people accountable for their operation.

Knowledge workers have a related responsibility. Sensitive internal material can reach AI tools through prompts, uploaded files, connected drives, or automated retrieval. Clear information boundaries still matter when a security gateway is present.

This is why continuous assurance should be treated as a process, not a purchase. Technology can automate discovery, testing, monitoring, and evidence collection. People must still define acceptable behavior and respond when conditions change.

Fortinet’s acquisition creates a plausible foundation for that process. Evidence of successful deployments must follow.

What to Watch After the Google News Headlines

Three signals will show whether Fortinet bought a strategic product layer or only accelerated its AI security roadmap on paper.

The first signal is a concrete integration release. Fortinet should identify which Virtue AI capabilities are available through FortiAIGate or the wider Security Fabric.

A credible release should include shared policy management, coordinated alerts, agent and tool discovery, and a clear response workflow. Customers should not need to move manually between unrelated dashboards to investigate one incident.

Documentation will reveal as much as the launch announcement. Architecture diagrams, deployment requirements, supported frameworks, data flows, and policy examples can show whether the products genuinely operate together.

Fortinet should also explain migration for existing Virtue AI customers. Those organizations need product support, roadmap continuity, and clarity about contracts and data handling.

If Fortinet delivers an integrated release quickly, it will strengthen the argument that Virtue AI filled a defined platform gap. A vague roadmap or repeated delay would weaken that interpretation.

The second signal is measurable technical validation. Fortinet should publish test methods, detection results, latency measurements, and false-positive data across representative agent workflows.

Attack-category counts are useful for describing scope, but buyers need outcomes. They need to understand how controls perform against prompt injection, data leakage, malicious tools, unsafe code, and multi-step agent manipulation.

Independent evaluation would carry more weight than internal demonstrations. Research partners, customers, or neutral testing organizations could examine whether the platform detects attacks without making ordinary workflows unusable.

Fortinet should report limitations as well as successes. AI behavior is probabilistic, and no guardrail can guarantee universal protection. Clear boundaries make deployment decisions safer.

Evidence of strong performance would distinguish the acquisition from market positioning. Persistent ambiguity would leave Palo Alto Networks, Cisco, Check Point, and specialists room to challenge Fortinet’s claims.

The third signal is customer adoption. Fortinet must show that organizations are activating these capabilities in production, not merely purchasing them as part of larger agreements.

Useful adoption evidence would include the number of protected applications, monitored agents, connected tools, or production policies. Fortinet does not need to expose sensitive customer details to report meaningful operational metrics.

Customer stories should describe specific environments and results. A detailed account of preventing an unsafe tool call offers more insight than a broad statement about improving AI confidence.

Adoption will also test the platform strategy. Customers may prefer security controls from an existing network vendor, especially when that choice simplifies procurement and incident operations.

Other buyers may favor independent products that work across several security platforms. Fortinet must demonstrate enough interoperability to avoid making AI protection feel like an extension available only inside a closed environment.

These three signals should shape how readers interpret future Google News updates about the acquisition. Product integration, technical validation, and production adoption matter more than another announcement about portfolio breadth.

Fortinet has made a logical competitive move. Virtue AI adds specialized research, automated testing, agent monitoring, and runtime controls to an established cybersecurity platform.

The acquisition also gives Fortinet a direct answer to rivals that bought Protect AI, Robust Intelligence, and Lakera. That answer remains incomplete until customers can compare integrated products under real conditions.

For security leaders, the immediate action is not to replace an architecture based on acquisition news. It is to inventory active agents, document their permissions, map their tool connections, and identify where runtime controls belong.

Then ask Fortinet and its competitors the same questions. Which changes trigger new tests? What data leaves the environment? How are false positives measured? Can policies follow an agent across models and tools?

Those answers will reveal whether continuous AI assurance is becoming an operational security discipline or remaining a persuasive marketing phrase.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page