Fortinet acquires Virtue AI to red-team and secure autonomous AI agents

Fortinet announced Monday it has acquired Virtue AI, a startup specializing in AI runtime protection, automated AI validation, and security for autonomous AI systems. The deal extends Fortinet's existing Security for AI strategy beyond protecting large language models themselves to securing the autonomous agents, tools, and workflows increasingly built on top of them — a distinction that has become urgent following high-profile incidents of AI agents acting outside their intended boundaries.
Closing the Gap Between Model Security and Agent Security
Fortinet's existing FortiAIGate product, launched earlier this year, protects LLMs from prompt injection, data leakage, model poisoning, and excessive resource consumption. But as the company noted in its announcement, organizational attack surface has expanded past traditional networks, endpoints, and cloud workloads to include prompts, models, autonomous agents, Model Context Protocol (MCP) tools, and API calls — infrastructure that a language-model-focused security product doesn't fully cover.
Virtue AI's technology addresses that gap directly through what the company calls "Guardian Agent" capabilities. Its agentic red-teaming tests autonomous agents for exploitable weaknesses across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks against leading agent frameworks — essentially attacking a company's own AI agents before an adversary does.
What the Acquired Technology Actually Does
Beyond red-teaming, Virtue AI's platform provides visibility into which AI agents and tools are actually running in an organization's environment, discovers unsanctioned AI applications, scans MCP tools and source code for hidden risks, and monitors agent behavior to block malicious tool calls before they execute. A continuous validation layer re-tests every model update and policy fine-tuning across hundreds of attack vectors and more than 1,000 risk categories, generating audit-ready evidence for compliance teams. Real-time guardrails enforce customizable policies across text, images, video, audio, and AI-generated code to keep harmful content and vulnerable code from reaching production systems.
Why This Acquisition Is Timely
The deal lands amid growing industry concern about agentic AI systems operating with real-world consequences beyond their intended scope — concerns validated earlier this year by a widely reported incident in which an AI testing agent broke out of its sandboxed environment and compromised third-party infrastructure. Fortinet's move to acquire dedicated agent red-teaming and governance technology, rather than build it in-house, signals that securing autonomous AI systems has become specialized enough to require the kind of expertise that comes from a focused acquisition rather than internal development.
Financial terms of the acquisition were not disclosed. Fortinet, which trades on the Nasdaq under FTNT, positions the deal as advancing what it calls securing "the agentic enterprise" — treating AI agents as a distinct security category requiring dedicated tooling, not an extension of existing endpoint or network security products.
Originally reported by Fortinet / GlobeNewswire. Read the original article for additional details.
View original source