Fortinet Acquires Virtue AI: A Major Step Toward Securing the Agentic AI Enterprise

Artificial intelligence is rapidly becoming part of enterprise infrastructure. Organizations are moving beyond traditional chatbots and copilots toward AI agents that can access applications, interact with data, execute tasks, and make decisions with increasing levels of autonomy.

As this transformation accelerates, securing AI systems throughout their lifecycle is becoming a critical cybersecurity requirement.

A significant development in this area is Fortinet’s acquisition of AI security company Virtue AI. The acquisition is intended to strengthen Fortinet’s capabilities for securing AI models, applications, and agentic systems. Financial terms were not disclosed, although Fortinet indicated that the transaction was immaterial to its business.

Why This Acquisition Matters

Virtue AI developed an enterprise AI security and governance platform focused on automated testing, real-time protection, and compliance oversight for AI models, conversational applications, and autonomous agents.

Its technology includes automated red teaming designed to identify vulnerabilities across numerous attack vectors and risk categories. The platform also evaluates autonomous agents in simulated enterprise environments, including their tool usage, system access, and multi-step workflows.

This is important because traditional application security approaches may not fully address the behavior of AI systems.

An AI agent can potentially:

• Access enterprise applications
• Retrieve sensitive information
• Interact with APIs and external tools
• Generate and execute code
• Perform multi-step tasks
• Communicate with other systems or agents
• Make decisions based on changing inputs

Each capability introduces additional security considerations.

AI Agents Are Creating a New Security Layer

Traditional cybersecurity focuses heavily on users, devices, applications, networks, and data.

Agentic AI introduces another layer: autonomous software identities capable of taking actions.

Organizations therefore need to understand not only who has access to a system, but also which AI agents can access it, what those agents can do, and whether their behavior remains within approved boundaries.

A compromised or manipulated AI agent could potentially become a pathway into other enterprise systems.

This makes agent identity, authorization, runtime monitoring, and behavioral controls increasingly important.

Continuous AI Security Testing

One of the notable aspects of Virtue AI’s technology is its emphasis on continuous AI validation and automated red teaming.

Security testing for AI should not be limited to the development stage.

AI systems can change as models, prompts, tools, integrations, policies, and datasets evolve.

Organizations should therefore consider continuous testing for:

• Prompt injection
• Data leakage
• Model manipulation
• Excessive permissions
• Unsafe tool usage
• Insecure API interactions
• Malicious code generation
• Unauthorized agent actions
• Model and agent behavior changes
• Supply chain risks

Continuous validation can help identify weaknesses before they become operational security incidents.

Runtime Guardrails Are Becoming Essential

Security testing identifies weaknesses before deployment, but organizations also need protection while AI systems are operating.

According to SecurityWeek, Virtue AI’s technology applies runtime guardrails across text, code, audio, video, and image processing. It can monitor AI agents, block unsafe actions, scan generated code and tools for vulnerabilities, and enforce customizable security policies.

This represents an important shift in AI security.

Instead of relying entirely on predeployment testing, organizations can combine testing with runtime controls.

The objective is to identify risky behavior and prevent potentially harmful actions before they affect enterprise systems.

AI Governance and Compliance Must Work Together

AI governance cannot be treated as a separate policy exercise.

Security, privacy, compliance, risk management, and AI governance need to operate together.

Organizations should establish controls covering:

AI Asset Discovery

Maintain an inventory of AI models, agents, applications, APIs, datasets, and third party AI services.

Identity and Access Management

Give AI agents clearly defined identities and permissions.

Least Privilege

Limit agents to the minimum access required to perform their approved functions.

Runtime Monitoring

Monitor AI interactions, tool usage, data access, and agent behavior.

Data Protection

Prevent sensitive information from being unnecessarily exposed to AI models and applications.

Security Validation

Continuously test AI systems for vulnerabilities and unsafe behavior.

Policy Enforcement

Create technical guardrails that enforce organizational AI security policies.

Auditability

Maintain appropriate records of AI activity, security testing, policy decisions, and compliance controls.

The Enterprise AI Attack Surface Is Expanding

As organizations deploy AI across departments, the attack surface can expand rapidly.

An AI application connected to a customer database creates different risks from a standalone chatbot.

An AI coding agent with access to source repositories creates different risks from an internal analytics assistant.

An autonomous agent connected to financial systems requires significantly stronger controls than an AI tool used only for document summarization.

Security teams therefore need to evaluate AI systems based on their capabilities, permissions, data access, integrations, and potential business impact.

Industries That Need Strong AI Security

The growing adoption of AI agents has implications across multiple industries.

Financial Services

Banks, FinTech companies, insurance providers, and investment organizations can use AI for fraud detection, customer service, financial analysis, and automation.

COE Security can help assess AI applications, protect sensitive financial data, test AI security controls, and support compliance programs.

Healthcare

Healthcare organizations are increasingly adopting AI for clinical workflows, administration, research, and patient services.

COE Security can help evaluate AI systems, protect sensitive healthcare information, conduct security testing, and strengthen data governance.

Retail and E-Commerce

Retail organizations use AI for personalization, customer service, inventory management, fraud detection, and marketing.

COE Security can help secure customer-facing AI applications, APIs, cloud environments, and third party integrations.

Manufacturing

Manufacturers are adopting AI across production, supply chain management, industrial environments, and operational technology.

COE Security can help assess AI, IoT, cloud, application, network, and OT security risks.

Government

Government agencies increasingly need to protect sensitive citizen information while adopting AI for public services and operational efficiency.

COE Security can help strengthen AI governance, data protection, identity security, application security, monitoring, and compliance controls.

Technology and SaaS

Technology companies developing AI applications and platforms face security challenges throughout the development lifecycle.

COE Security can support secure AI development, AI penetration testing, application security, cloud assessments, API testing, and DevSecOps programs.

What Organizations Should Do Now

The Fortinet and Virtue AI development highlights an important lesson: AI security needs to be built into the architecture rather than added after deployment.

Organizations preparing for broader AI adoption should consider:

• Establishing an AI asset inventory
• Identifying AI agents and their permissions
• Applying least privilege to AI systems
• Implementing strong identity controls
• Conducting AI red team assessments
• Testing for prompt injection and data leakage
• Monitoring agent behavior in real time
• Protecting APIs and connected applications
• Validating AI generated code and tool usage
• Establishing human oversight for high-risk actions
• Implementing data governance controls
• Assessing third party AI providers
• Maintaining AI security logs and audit trails
• Integrating AI security into the SSDLC
• Continuously reviewing AI compliance requirements

The Bigger Picture

The acquisition demonstrates how quickly AI security is becoming a core part of enterprise cybersecurity.

Fortinet has stated that it intends to leverage Virtue AI’s capabilities in agentic system red teaming, agent protection and governance, continuous AI validation, and real-time guardrails.

This direction reflects a broader industry shift.

AI security is moving from model testing alone toward continuous protection across the entire AI lifecycle.

Organizations will increasingly need to secure AI during development, deployment, integration, and runtime.

Conclusion

The Fortinet acquisition of Virtue AI is another indication that enterprise AI security is becoming a strategic cybersecurity priority.

As AI agents gain the ability to interact with applications, data, APIs, and enterprise infrastructure, organizations need stronger controls around identity, access, behavior, testing, monitoring, and governance.

The future of enterprise AI will not depend only on how capable AI systems become. It will also depend on how securely organizations can control and monitor them.

Organizations that adopt continuous AI security validation, runtime protection, strong governance, and secure development practices will be better positioned to benefit from AI while reducing cybersecurity and compliance risks.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services

In addition, COE Security helps organizations strengthen AI security and governance through AI risk assessments, AI penetration testing, adversarial testing, AI agent security assessments, prompt injection testing, model validation, runtime security assessments, API security testing, cloud security assessments, identity and access management reviews, data governance, vulnerability management, DevSecOps consulting, third party AI risk assessments, and compliance readiness programs.

For financial services and FinTech organizations, we help secure AI systems handling financial and customer information while supporting cybersecurity and compliance requirements.

For healthcare organizations, we help protect sensitive information and assess AI applications, cloud infrastructure, APIs, and supporting systems.

For retail and e-commerce organizations, we help secure customer-facing AI applications, payment-related environments, APIs, cloud systems, and third party integrations.

For manufacturing organizations, we help assess AI, IoT, OT, cloud, network, and application security risks across connected environments.

For government organizations, we help strengthen AI governance, identity security, data protection, application security, monitoring, and compliance programs.

For technology and SaaS companies, we help integrate security into AI development, agentic workflows, applications, APIs, cloud environments, and software development processes.

Our goal is to help organizations adopt AI securely, identify vulnerabilities proactively, protect sensitive information, and build resilient and compliant digital environments.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.

Click to read our LinkedIn feature article