Fortinet Buys AI Security Startup Virtue AI
The cybersecurity giant adds a specialist platform for testing and protecting AI models, chatbots, and autonomous software agents, as the market for AI security tools heats up fast.

Key points
- Fortinet announced the acquisition of Virtue AI on Monday, with financial terms undisclosed.
- Virtue AI raised $30 million in seed and Series A funding in 2025 before the deal closed.
- Fortinet described the purchase price as "immaterial" to its finances, a signal of strategic rather than transformational intent.
- Virtue AI's platform tests AI systems for weaknesses using more than 100 proprietary attack algorithms across hundreds of risk categories.
- The deal gives Fortinet tools to protect autonomous AI agents, software programs that take actions and make decisions without a human approving each step.
Fortinet, one of the largest cybersecurity companies in the world, has acquired Virtue AI, a startup that builds security tools specifically for artificial intelligence systems. The deal was announced Monday, no price attached beyond Fortinet calling it "immaterial" to its bottom line.
What does Virtue AI's platform actually do?
Virtue AI's platform has two jobs: find weaknesses in AI systems before attackers do, and block dangerous behaviour while those systems run.
On the finding-weaknesses side, the platform performs automated red-teaming, playing attacker and probing an AI model for flaws using more than 100 proprietary attack algorithms across hundreds of risk categories. For autonomous AI agents, the kind of software that can execute multi-step workflows without asking permission, it simulates dozens of enterprise scenarios to test whether an agent can be manipulated into harmful actions.
On the keeping-things-safe side, the platform watches live AI systems in real time. It applies guardrails, rules that stop an AI producing or acting on harmful outputs, across text, images, audio and video. If an autonomous agent is about to take an unsafe action, the platform can block it before execution. It also scans generated code for vulnerabilities and enforces customisable security policies.
Why does this matter to ordinary people?
More companies are plugging AI tools into products ordinary people use every day: customer service chatbots, booking systems, medical record software. When those systems misbehave, either because of flaws or deliberate manipulation, real customers and employees pay the price.
Attacks on AI are a genuine and growing problem. Prompt injection, where a criminal hides malicious instructions inside text that an AI reads and obeys, is the closest thing the field has to a classic web-security trick in new clothes. It's not theoretical: researchers have demonstrated it against commercial products. Training-data poisoning, where corrupted data is fed into a model during development to make it misbehave later, is another threat Virtue AI's platform targets. We've tracked the parallel rush to secure autonomous agents since our Cyera-Oasis coverage in late July, and Fortinet's move confirms the pattern: nobody wants to be the company whose AI agent ran wild.
| Detail | Figure |
|---|---|
| Virtue AI funding raised (2025) | $30 million |
| Attack algorithms in the platform | 100+ proprietary |
| Attack vectors and risk categories covered | Hundreds |
| Enterprise scenarios simulated for agents | Dozens |
| Acquisition price disclosed | No |
Fortinet CEO Ken Xie framed the purchase as part of a longer plan, saying that Virtue AI's technology would help customers "govern and protect AI systems throughout their lifecycle while operating them confidently at enterprise scale."
That is a reasonable aspiration. Whether the tools deliver is something the market will answer over the next year or two, as Fortinet integrates Virtue AI into its existing product line.
Common questions
Does this affect me if I use a product that runs on Fortinet software?
Not directly, not yet. Fortinet will take time to integrate Virtue AI's tools, so changes to what end users see will be gradual.
Are AI systems genuinely at risk, or is this just marketing?
The risks are real, even if the marketing is often overblown. Prompt injection attacks have been demonstrated against commercial AI products, and researchers have shown autonomous agents can be tricked into harmful actions. The acquisition is a bet that enterprises will pay for dedicated tooling rather than bolt-on fixes, and that bet looks increasingly sound.



