Fortinet Buys AI Security Startup Virtue AI

The cybersecurity giant adds a specialist platform for testing and protecting AI models, chatbots, and autonomous software agents, as the market for AI security tools heats up fast.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek matte-black padlock resting on a softly glowing computer keyboard, cool blue and teal rim ligh
Share

Key points

  • Fortinet announced the acquisition of Virtue AI on the same day SecurityWeek reported it, with financial terms undisclosed.
  • Virtue AI raised $30 million in seed and Series A funding in 2025 before the deal closed.
  • Fortinet described the purchase price as "immaterial" to its finances, suggesting a relatively small outlay for a strategic buy.
  • Virtue AI's platform tests AI systems for weaknesses using more than 100 proprietary attack methods across hundreds of risk categories.
  • The deal gives Fortinet tools to protect autonomous AI agents, which are software programs that can take actions and make decisions without a human approving each step.

Fortinet, one of the largest cybersecurity companies in the world, has acquired Virtue AI, a startup that builds security tools specifically for artificial intelligence systems. The deal was announced Monday, with no price tag attached beyond Fortinet calling it "immaterial" to its bottom line.

So what did Fortinet actually buy?

What does Virtue AI's platform actually do?

Virtue AI's platform has two main jobs: find weaknesses in AI systems before criminals do, and block dangerous behaviour while those systems are running.

On the finding-weaknesses side, the platform performs what security professionals call red-teaming, meaning it plays the role of an attacker and probes an AI model for flaws. It uses more than 100 proprietary attack methods spread across hundreds of risk categories. For autonomous AI agents, specifically the kind of software that can browse the web, write code, or place orders on your behalf without asking permission first, it simulates dozens of realistic business scenarios to see whether the agent can be tricked into doing something harmful.

On the keeping-things-safe side, the platform watches live AI systems in real time. It applies guardrails, which are rules that stop an AI from producing or acting on harmful outputs, across text, images, audio, video, and code. If an autonomous agent is about to take an unsafe action, the platform can block it before it happens.

Why does this matter to ordinary people?

More companies are plugging AI tools into the products and services ordinary people use every day, from customer service chatbots to booking systems to medical record software. When those AI systems misbehave, either because they were built with flaws or because someone deliberately manipulated them, real customers, patients, or employees can be affected.

Attacks on AI systems are a real and growing problem. Prompt injection, where a criminal hides malicious instructions inside text that an AI reads and then obeys, is the closest thing the field has to a classic web-security trick dressed up in new clothes. Training-data poisoning, where bad data is fed into a model during development to make it behave badly later, is another. Virtue AI's platform is designed to catch both kinds of problem.

Detail Figure
Virtue AI funding raised (2025) $30 million
Attack algorithms in the platform 100+ proprietary
Attack vectors and risk categories covered Hundreds
Enterprise scenarios simulated for agents Dozens
Acquisition price disclosed No

Fortinet CEO Ken Xie framed the purchase as part of a longer plan: "AI is fundamentally changing enterprise computing, and security must evolve just as quickly."

That is a reasonable thing to say. Whether the tools deliver is a question the market will answer over the next year or two, as Fortinet folds Virtue AI's technology into its existing product line.

Common questions

Does this affect me if I use a product that runs on Fortinet software?

Not directly, at least not yet. Fortinet will take time to integrate Virtue AI's tools into its existing products, so changes to what end users see will be gradual.

Are AI systems genuinely at risk, or is this just marketing?

The risks are real, even if the marketing around them is often overblown. Prompt injection attacks, for example, have been demonstrated against commercial AI products, and researchers have shown that autonomous agents can be manipulated into taking harmful actions.

© 2026 Threat Vectr