Skip to content

Security2 publishers3 min readPublished

Fortinet Buys Virtue AI, and AI Red-Teaming Becomes a Suite Feature

Fortinet says the price was immaterial to its business. For teams budgeting a standalone AI red-teaming and guardrails tool, that is the number that matters.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Fortinet on Monday announced the acquisition of AI security company Virtue AI.
  • Virtue AI's enterprise security and governance platform provides automated testing, real-time protection and compliance oversight built for AI models, conversational applications and autonomous agents.
  • Financial terms of the deal were not disclosed, but Fortinet said the amount paid was immaterial to its business.
  • One platform component conducts automated red-teaming using over 100 proprietary attack algorithms across hundreds of attack vectors and risk categories.
  • Agentic system red-teaming tests autonomous agents for exploitable weaknesses across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks against leading agent frameworks.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Fortinet announced on Monday that it has acquired Virtue AI, whose platform combines automated testing, real-time protection and compliance oversight for AI models, conversational applications and autonomous agents [1][2]. Terms were not disclosed, but Fortinet said the amount it paid was immaterial to its business [3], which is the most operationally useful disclosure in the whole release.

The acquired capability set is essentially the standalone AI security category as currently sold. Virtue AI's red-teaming component uses more than 100 proprietary attack algorithms across hundreds of attack vectors and risk categories [4]. For agents, testing runs across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks against leading agent frameworks [5]. In production, the platform enforces customizable policies across text, images, video, audio and AI-generated code, monitors agents, and blocks unsafe or malicious tool calls before they execute [6][7]. It also discovers unsanctioned AI applications and agents, scans MCP tools and source code, and generates audit-ready evidence as models are updated and fine-tuned [7][8].

Fortinet is folding this into an existing stack rather than starting a line of business. It shipped FortiAIGate earlier this year to protect large language models against prompt injection, data leakage, model poisoning and excessive resource consumption [9], and it positions the Virtue AI capabilities as complementary to that product and to FortiGuard Labs threat intelligence inside its Security Fabric [10]. The stated rationale is lifecycle coverage: Fortinet frames the expanded attack surface as prompts, models, agents, MCP tools, API calls and AI infrastructure [11], and Ken Xie said the technology advances a vision for "continuous AI assurance" across the AI system lifecycle [12].

Two numbers frame the budget question. Fortinet cites Gartner projecting that the market for securing AI ecosystems and agents will grow from $2.8 billion in 2026 to $16.4 billion by 2030 [13], roughly a six-fold increase over four years [14]. Against that, Virtue AI raised $30 million in seed and Series A funding during 2025 [15], and the purchase price was small enough that Fortinet declared it immaterial [3]. Immateriality is measured against Fortinet's balance sheet, not against a startup's last round, so it does not establish a valuation. It does indicate that a platform vendor did not have to stretch to buy a full red-teaming and guardrails product, in a year in which SecurityWeek's M&A tracker has catalogued more than 240 deals [16] alongside far larger transactions such as Cyera's $1 billion acquisition of Oasis Security [17].

One caution on diligence: the two published accounts of the same platform do not agree on scale. SecurityWeek describes hundreds of attack vectors and risk categories [4], while the vendor-supplied breakdown says hundreds of attack vectors and more than 1,000 risk categories [18]. Coverage counts in this category are marketing artefacts until someone maps them to your agents and your tools.

What to watch: whether these capabilities arrive as a licensed add-on or get absorbed into Fabric entitlements at renewal; whether Virtue AI's agent testing continues to support frameworks Fortinet does not otherwise sell against; and how quickly the remaining independent guardrail vendors are bought by platform incumbents on similarly modest terms [3][16].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories