Skip to content
Software Supply Chain Security

Fortinet’s AI Security Step Forward: Virtue AI

Fortinet Virtue AI

Fortinet has announced the acquisition of AI security company Virtue AI, signaling a focused push to broaden enterprise protection for the next generation of AI systems. As organizations increasingly deploy AI models, conversational applications, and autonomous agents, the attack surface expands beyond traditional software—and security needs to keep pace.

According to Fortinet, Virtue AI’s enterprise security and governance platform is built to provide automated testing, real-time protection, and compliance oversight tailored to AI workloads. The company also says the technology helps teams validate AI systems throughout their lifecycle, from evaluation to live operation.

What Fortinet Virtue AI adds to AI security

The key value of the Virtue AI platform lies in its emphasis on AI-specific testing and controls. Instead of treating AI as a generic application layer, the platform is designed to evaluate how AI models and agent systems behave under pressure, while also guarding against unsafe actions during operation.

Fortinet stated that the acquisition strengthens its AI security offering for AI models, applications, and agentic systems. It plans to apply Virtue’s capabilities—particularly around agent system red teaming, agent protection and governance, continuous AI validation, and real-time runtime guardrails.

Automated red teaming for AI vulnerabilities

One of the platform’s components focuses on automated red teaming. In practice, this means running security testing designed to uncover vulnerabilities before deployments reach production environments.

Virtue AI’s automated approach uses more than 100 proprietary attack algorithms. These are applied across hundreds of attack vectors and risk categories, helping teams explore a wide range of threat scenarios. By scaling red-team-style evaluation, the platform aims to identify weaknesses that could otherwise be missed during manual testing.

Evaluating autonomous agents in simulated scenarios

For autonomous systems, the platform includes testing that simulates enterprise conditions rather than relying on simplistic checks. Fortinet says the environment can represent dozens of enterprise scenarios to evaluate how agents use tools, access systems, and perform multi-step execution workflows.

This kind of evaluation is important because agent behavior can change based on context. A system that looks safe in one situation may take unsafe actions when exposed to different inputs, permissions, or workflow paths. By testing multi-step processes, the platform targets the ways agents may chain actions in ways security teams need to understand early.

Real-time runtime guardrails across text and more

When AI systems move from test to live operations, the platform shifts from evaluation to protection. Fortinet says Virtue AI applies real-time runtime guardrails during processing across multiple modalities, including text, code, audio, video, and image handling.

The goal is to reduce the chance that an AI system performs unsafe operations while processing user inputs or generating outputs. Instead of waiting for issues to surface after deployment, the platform works to intervene at runtime based on the policies configured by defenders.

Monitoring agents and blocking unsafe actions

Beyond guarding processing pipelines, the platform also monitors agents to prevent unsafe actions before they are executed. Fortinet describes active oversight that blocks risky behavior in the moments where decisions are made.

In addition, the platform scans generated code and tools for vulnerabilities. This is relevant because many AI systems can produce code snippets or select tools dynamically. If those artifacts include insecure patterns or weaknesses, a monitoring and scanning layer can help reduce exposure.

Customizable governance and continuous validation

Security teams need more than alerts—they need enforceable governance. Fortinet says the platform supports customizable security policies, which allows organizations to align enforcement with internal requirements and risk tolerance.

It also emphasizes continuous AI validation. In other words, testing and assurance are designed to be ongoing rather than a one-time activity. This supports the reality that AI systems evolve over time as models are updated, prompts change, and agents gain new capabilities.

Deal details and what Fortinet says it will do next

Financial terms of the acquisition were not disclosed. Fortinet noted that the amount paid is immaterial to its business. The company also framed the move as part of a broader shift in how enterprises approach AI assurance and protection.

Fortinet’s CEO and founder Ken Xie said AI is fundamentally changing enterprise computing, and security must evolve quickly to match. He highlighted Virtue AI’s role in advancing continuous AI assurance, helping customers govern and protect AI systems through their lifecycle while operating at enterprise scale.

Why this acquisition matters for enterprise teams

Virtue AI’s platform focuses on three security needs that are increasingly relevant for enterprises: testing AI behavior before deployment, enforcing runtime protection while systems operate, and governing the policy and compliance side of AI operations.

By combining automated red teaming, simulated agent scenarios, and runtime guardrails, the approach aims to cover both the pre-production and operational phases. For organizations, this can reduce blind spots—especially in agentic setups where systems may take actions across multiple steps and tools.

Background on Virtue AI funding

Virtue AI reportedly raised $30 million in seed and Series A funding in 2025. With the acquisition, Fortinet gains technology purpose-built for the security challenges tied to AI models, conversational applications, and autonomous agents.

AI security moving toward lifecycle assurance

Fortinet’s announcement reflects a broader industry direction: AI security is moving from one-off assessments toward lifecycle assurance. As enterprises run AI systems in real environments, they need controls that can test continuously, enforce guardrails at runtime, and support policy-based governance.

The integration of Virtue AI’s red teaming for agent behavior and runtime protections across text, code, and other modalities may help organizations manage risk more systematically. In practice, it suggests a shift toward security platforms that treat AI systems as dynamic components—not static apps.

Conclusion

The Fortinet Virtue AI acquisition adds a specialized AI security platform to Fortinet’s portfolio. With automated red teaming, enterprise scenario simulation for agents, real-time runtime guardrails, and governance capabilities, the move is designed to strengthen protection for AI models, applications, and agentic systems.

While the financial details remain undisclosed, Fortinet’s stated intent is clear: help customers govern and protect AI throughout its lifecycle, with continuous validation and guardrails that work during live operation.

Source: https://www.securityweek.com/fortinet-acquires-ai-security-company-virtue-ai/