Decoding the world of cybersecurity

Fortinet buys Virtue AI for agent security

Fortinet has acquired Virtue AI, adding automated AI testing, runtime controls, agent visibility, and Model Context Protocol scanning to its security platform.

Fortinet buys Virtue AI for agent security
Summary
  • Virtue AI adds agentic red-teaming, runtime guardrails, AI tool discovery, source scanning, and continuous validation.
  • Fortinet says the acquisition complements its existing FortiAIGate product and broader Security for AI strategy.
  • Financial terms were not disclosed, although Fortinet said the consideration was immaterial to its business.

Fortinet has acquired AI-security specialist Virtue AI, adding agent testing, runtime controls, and governance technology as established security vendors compete to absorb a new layer of enterprise infrastructure into broader platforms.

Fortinet said Virtue AI will become part of its Security for AI strategy and extend controls already provided through FortiAIGate. Financial terms were not disclosed, although Fortinet said the consideration was immaterial to its business.

Virtue AI develops technology for automated testing and runtime protection of AI applications and autonomous agents. Its capabilities include red-teaming agents, monitoring their behaviour, identifying unauthorised AI tools, scanning Model Context Protocol components and source code, and blocking certain tool calls before execution.

The company also provides continuous validation intended to retest AI systems when models or policies change, alongside guardrails covering text, images, audio, video, and generated code.

Those capabilities illustrate how the AI-security market is dividing into several different control planes. Conventional application security can test the software surrounding an AI model, while data-security products monitor information moving into and out of applications. Agentic systems create additional questions around prompts, model behaviour, tool permissions, memory, external APIs, MCP servers, and autonomous actions.

Fortinet’s acquisition targets that latter layer. The company says Virtue AI can test autonomous agents across more than 50 sandboxed environments and 14 higher-risk domains, including simulated prompt-injection and MCP attacks.

The claims are vendor descriptions rather than independent performance assessments, but the product direction is commercially revealing. Large security suppliers increasingly want AI controls to sit inside existing network, cloud, endpoint, application, and policy platforms rather than operate as isolated specialist products.

That creates potential advantages for procurement and enforcement. If an organisation can connect AI runtime decisions to identity, network policy, endpoint telemetry, and application security, an agent’s actions can be assessed against a wider set of signals.

It also creates another consolidation question. AI security remains a young category with rapidly changing terminology and controls. Folding specialist technologies into large security platforms can accelerate distribution, but customers still need to distinguish between separate problems such as model evaluation, prompt injection, agent authorisation, data leakage, software vulnerabilities, and governance evidence.

Those functions are not interchangeable merely because they all involve AI.

The timing follows rapid adoption of autonomous development, support, research, and business-process agents with increasingly broad permissions. Recent controlled research has shown agents altering systems, reaching external infrastructure, and conflicting with other autonomous systems when environment boundaries or objectives are poorly specified.

Security products are consequently moving from protecting an AI chatbot’s inputs and outputs towards monitoring software that can take actions on behalf of a user.

Fortinet says Virtue AI will extend its existing AI-security capabilities from development into runtime, while producing evidence intended to support security and compliance reviews. The company already sells networking, endpoint, cloud, application, and security-operations technology, giving it several potential enforcement points for those controls.

The acquisition does not by itself establish whether a consolidated approach will outperform specialist AI-security platforms. It does show where large vendors expect enterprise spending to move: towards controls that can evaluate what autonomous systems are permitted to do, observe what they actually do, and intervene before a tool call becomes an operational action.

×