Fortinet Acquires Virtue AI to Secure Autonomous AI Agents
The acquisition integrates runtime protection and automated red-teaming into Fortinet's AI-Native Security Fabric to combat agentic risks.
Fortinet has acquired Virtue AI, a specialist in security and governance for AI models and autonomous agents, to secure the expanding attack surface of enterprise AI. The move integrates advanced runtime protection and automated validation into Fortinet's AI-Native Security Fabric.
The acquisition brings specific capabilities for scanning Model Context Protocol (MCP) tools, monitoring the behavior of AI agents, and blocking malicious tool calls. According to industry reports, Virtue AI's automated red-teaming capabilities are extensive, running across hundreds of attack vectors and more than 1,000 risk categories. Financial terms of the transaction were not disclosed, though the amount paid is considered immaterial to Fortinet's overall business.
The Shift to Agentic Security
This strategic expansion builds upon the foundation of FortiAIGate, a tool Fortinet introduced earlier in 2026. While FortiAIGate was designed to protect large language models (LLMs) from foundational threats such as prompt injection, data leakage, and model poisoning, the addition of Virtue AI addresses a more complex operational phase. As enterprises move AI agents from experimental pilots into full production, these agents are granted deeper access to sensitive corporate data and critical business processes, creating a necessity for continuous validation and real-time runtime controls.
Industry Implications
The acquisition signals a broader industry shift toward "agentic security." Unlike static AI models, autonomous agents can take actions within a corporate environment, representing a new and volatile risk vector for infrastructure. By absorbing Virtue AI's technology, Fortinet is positioning itself to offer a full-lifecycle security approach—spanning from the initial development phase to active production—specifically tailored for the unique vulnerabilities of autonomous systems.
What to Watch
Market observers will now look for how these capabilities are deployed across Fortinet's existing security ecosystem. The primary focus remains on whether the integration of MCP tool scanning and agent behavior monitoring can effectively preempt the "hallucination-driven" or malicious tool calls that often plague autonomous AI deployments. While the core technology is now integrated, the effectiveness of these controls in diverse enterprise environments remains the next critical benchmark.