Fortinet Acquires Virtue AI for Agent Security
Fortinet announced on August 17 that it acquired Virtue AI, an AI runtime protection and automated validation company, to expand security coverage for AI models, applications, and agentic systems. Financial terms were not disclosed, according to Investor's Business Daily. Fortinet said Virtue AI's capabilities include agentic red-teaming, runtime guardrails, MCP tool scanning, and continuous validation across model updates.
Fortinet announced on August 17 that it acquired Virtue AI, a provider of AI runtime protection, automated AI validation, and security technology for autonomous AI systems. The transaction adds Virtue AI's technology to Fortinet's Security for AI portfolio, covering AI models, applications, and agentic systems across development and production runtime. Financial terms were not disclosed, according to Investor's Business Daily.
Fortinet's announcement frames the acquisition as an extension of its FortiAIGate offering, which the company introduced earlier in 2026 for protections including prompt-injection defense, data-loss prevention, model-poisoning mitigation, and controls for excessive resource consumption. The company described Virtue AI as adding continuous validation and runtime protections for agentic AI environments.
Capabilities cited in the acquisition
According to Fortinet, Virtue AI's technology includes agentic-system red-teaming across more than 50 sandboxed environments and 14 high-stakes domains. The company said these tests include simulated prompt-injection and Model Context Protocol, or MCP, attacks against leading agent frameworks.
Fortinet also listed the following Virtue AI capabilities:
- •Discovery of AI applications and agents operating in an environment, including unsanctioned tools.
- •Scanning of MCP tools and source code for hidden risks, plus monitoring of agent behavior and blocking of malicious tool calls.
- •Continuous validation across model updates and policy fine-tuning, with audit-ready evidence for security and compliance reviews.
- •Automated red-teaming across hundreds of attack vectors and more than 1,000 risk categories, including multimodal testing.
- •Configurable runtime guardrails for text, images, video, audio, and AI-generated code.
The stated coverage spans common agent-security concerns: an agent can receive untrusted input, invoke external tools, access data through APIs, and produce outputs that trigger subsequent actions. MCP tool integrations add another security boundary because tools expose an interface between a model or agent and external systems.
Runtime controls become a larger focus
Fortinet's acquisition announcement identifies prompts, models, agents, MCP tools, API calls, and AI infrastructure as parts of the expanded attack surface associated with enterprise AI deployments. Help Net Security and Industrial Cyber reported the same technical scope from Fortinet's announcement.
For security and ML engineering teams, continuous validation differs from a one-time pre-deployment red-team exercise. In comparable AI deployments, model updates, changed system prompts, new retrieval sources, revised tool permissions, and policy changes can alter behavior after an initial evaluation. Runtime monitoring and policy enforcement are therefore increasingly paired with offline testing in agentic-system security architectures.
Investor's Business Daily reported that Virtue AI is part of a broader set of Fortinet acquisitions, alongside Lacework, Next DLP, Perception Point, and Suridata. That reporting places the transaction within cybersecurity vendors' wider efforts to add cloud, data-protection, and AI security capabilities as enterprise infrastructure and threat operations incorporate more AI tooling.
Fortinet has not disclosed the purchase price. The announcement also does not provide a product-integration timeline or identify which Virtue AI capabilities are immediately available in Fortinet products.
Key Points
- 1Fortinet acquired Virtue AI to add runtime protection, validation, and governance capabilities for models, applications, and autonomous agents.
- 2Fortinet cites MCP scanning, malicious tool-call blocking, and agent red-teaming, addressing security boundaries beyond conventional LLM prompt filtering.
- 3Comparable agent deployments require repeated testing because model, policy, tool, and retrieval changes can alter runtime behavior after initial evaluation.
Scoring Rationale
The acquisition is a notable consolidation event in enterprise AI security, particularly for teams deploying agents with tools and MCP integrations. Its practical relevance depends on product integration details and deployment availability, neither of which Fortinet disclosed.
Sources
Primary source and supporting public references used for this report.
View 4 more sources
- Fortinet acquires Virtue AI to strengthen security for agentic AI systems, expand AI runtime protectionindustrialcyber.co
- Fortinet expands AI security portfolio with Virtue AI acquisitionhelpnetsecurity.com
- Fortinet, IBD Stock Of The Day, Steps Up AI Acquisitions To Build Cloud Platforminvestors.com
- Fortinet Acquires AI Security Company Virtue AIitsecuritynews.info
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

