Fortinet has acquired Virtue AI, an AI security company focused on runtime protection, automated validation and security for autonomous AI systems, as the cybersecurity vendor looks to extend its protection of enterprises adopting AI agents.
The acquisition, announced on August 19, expands Fortinet’s existing Security for AI strategy beyond protecting large language models to cover AI applications and agentic systems throughout their development and runtime lifecycle. Financial terms were not disclosed, although Fortinet said the consideration paid was immaterial to its business.
The move comes as enterprises increasingly deploy AI applications and autonomous agents, creating an attack surface that extends beyond conventional networks, endpoints, applications and cloud workloads. Prompts, models, agents, Model Context Protocol tools, API calls and AI infrastructure are becoming additional security concerns.
Fortinet had earlier introduced FortiAIGate to protect large language models against threats including prompt injection, data leakage, model poisoning and excessive resource consumption. Virtue AI is intended to extend that protection into the behaviour and security of AI applications and autonomous agents.
From AI security to continuous validation
A central component of Virtue AI’s technology is its Guardian Agent capability, which provides visibility into AI agents and tools while testing them for exploitable weaknesses.
Its agentic system red-teaming capabilities can test autonomous agents across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks against leading agent frameworks.
The technology also scans MCP tools and source code for potential risks, identifies unsanctioned AI applications and agents, monitors agent behaviour and can block malicious tool calls before they are executed.
For enterprises, the emphasis is on making AI security a continuous process rather than a point-in-time assessment. Virtue AI’s automated validation can identify risks following model updates and policy fine-tuning, while generating audit-ready evidence for security, risk and compliance teams.
The company says its automated red-teaming covers hundreds of attack vectors and more than 1,000 risk categories, alongside multimodal testing and on-demand reporting.
“AI is fundamentally changing enterprise computing, and security must evolve just as quickly,” said Ken Xie, Founder, Chairman of the Board and Chief Executive Officer, Fortinet. “Virtue AI’s technology will advance our vision for continuous AI assurance, helping customers govern and protect AI systems throughout their lifecycle while operating them confidently at enterprise scale.”
Guardrails move into runtime
The acquisition also brings real-time guardrails into Fortinet’s AI security portfolio. These controls can be configured across text, images, video, audio and AI-generated code to prevent harmful content, sensitive data, jailbreaks and vulnerable code from reaching users or downstream systems.
That runtime layer is important as enterprises move from experimenting with AI models to deploying agents capable of taking actions on their behalf. In such environments, security is no longer limited to determining whether a model produces an unsafe response. Organisations also need visibility into what an agent can access, which tools it can invoke and whether its actions conform to policy.
Fortinet intends to combine Virtue AI’s capabilities with its existing AI-native Security Fabric, coordinated enforcement mechanisms and FortiGuard Labs threat intelligence.
The company said the acquisition will complement FortiAIGate by adding automated validation and runtime protection for AI systems, while extending security coverage across networks, endpoints, clouds, applications and AI deployments.
The market opportunity is also expanding. Gartner estimates that spending on products and tools for securing AI ecosystems and AI agents will grow from $2.8 billion in 2026 to $16.4 billion by 2030.
For Fortinet, Virtue AI therefore adds another layer to an increasingly broad security proposition. The immediate objective is to protect AI systems not only when they are deployed, but as they are developed, modified, connected to tools and operated in production.
The acquisition reflects a broader shift in enterprise AI security, where the challenge is moving from protecting AI infrastructure to continuously validating what increasingly autonomous systems can do.