In recent years, the explosive growth of artificial intelligence (AI) tools and agents has reshaped the digital landscape and brought on many new and evolving risks. The deployment of autonomous AI agents in business environments extends risk beyond networks and endpoints, as these agentic tools are typically over-permissioned and under-monitored. They introduce new exposure points through prompts, models, model context protocol (MCP) tools, and API calls, all vectors that are ill-protected by traditional security measures. As AI adoption continues to expand, it is rapidly outpacing the security models that were built to govern it.
Where Existing AI Defenses Stopped Short
Fortinet’s existing AI protection measures, introduced earlier in the year as FortiAIGate, addressed the issues of prompt injection, data leakage, model poisoning, and excessive resource consumption at the model layer. This is significant in securing large language models (LLMs) against the myriad threats endemic to AI usage, but it is not fully effective in environments with agentic AI running.
Agentic systems also bring up the challenges associated with tool-calling and autonomous action, pushing risks beyond what generative AI tools introduce. Even with FortiAIGate’s added AI defenses, there remained a lifecycle gap between the development-time testing and runtime enforcement of AI security measures. Closing this gap is the motivation behind Fortinet’s recently announced acquisition of Virtue AI.
What Virtue AI Brings to the Table
Virtue AI offers a number of expanded capabilities in AI security that Fortinet will benefit from. Virtue’s agentic red-teaming across sandboxed environments and high-stakes domains is crucial for effectively securing AI-enhanced environments. Virtue AI also brings functionality in agent visibility, governance, and blocking of malicious tool calls, areas where existing AI security is often severely lacking.
The addition of Virtue’s continuous validation across model updates and provision of audit-ready evidence offers major benefits in AI governance and logging of important information. The acquisition also empowers Fortinet’s AI defenses with real-time guardrails that span across text, image, video, audio, and generated code.
Folding in Agent Security
The addition of Virtue AI’s capabilities will extend Fortinet’s agentic AI security offerings significantly. Virtue’s functionalities will be integrated into FortiGuard Labs’ threat intelligence with coordinated enforcement to offer organizations strong, reliable security throughout the AI lifecycle. The integration will extend FortiAIGate’s model-level safeguards into the realm of AI applications and agents with Virtue AI’s Guardian Agent abilities. Fortinet’s acquisition of Virtue is positioned alongside its existing AI security offerings, including the FortiGate Hyperscale Firewall, in the company’s portfolio.
The deal also sits within the context of the growth of the broader category: Gartner projects that the AI security market will expand from $2.8 billion in 2026 to $16.4 billion by 2030. With the market on the rise and predicted to grow steeply in the next few years, it is crucial for organizations and security leaders to look to deals like this for where the industry is headed.
What This Signals for Security Leaders
This deal communicates to the wider industry that leading companies like Fortinet are choosing to invest increasingly in AI security. Governance and validation are becoming continuous processes rather than point-in-time checks, requiring the advancement and expansion beyond what previously existing AI security is capable of.
Vendors are increasingly consolidating around full-lifecycle AI assurance over single-layer defenses, prioritizing efforts to secure AI tools and agents more thoroughly. In light of these trends in AI security, CISOs are facing mounting pressure to evaluate agent-level risk alongside model-level risk in order to sufficiently protect AI usage.
The Bigger Shift Underway
Agentic AI security is moving from emerging category to expected baseline as more and more major companies make it a central part of their security offerings. The next differentiator among vendors will be the depth of lifecycle coverage as the presence of agentic AI security becomes standard. Enterprises adopting agentic AI without securing this layer will inherit significant unmanaged risk, opening them up to extensive damage.