
Fortinet Buys Virtue AI to Red-Team Your AI Agents
Fortinet acquired Virtue AI on August 17, adding agentic red-teaming across 50 sandboxed environments and 1,000 risk categories to its security fabric.
The uncomfortable truth about autonomous agents is that nobody attacks them the way an attacker would. Fortinet moved to change that on August 17, 2026, announcing it had acquired Virtue AI, a startup whose main product is a machine that tries very hard to break your AI agents before somebody else does.
- Virtue AI's red-teaming runs autonomous agents through more than 50 sandboxed environments across 14 high-stakes domains
- Its continuous validation service automates red-teaming across more than 1,000 risk categories with audit-ready reporting
- Real-time guardrails apply policy across text, images, video, audio, and generated code
- Financial terms were not disclosed; Fortinet said the amount was immaterial to its business
What Agentic Red-Teaming Actually Tests
Traditional application security asks whether an input can reach a dangerous code path. Agent security has to ask something harder: whether a sequence of ordinary-looking interactions can talk a capable system into doing something it should not.
Virtue AI's platform, founded in 2024 and backed by roughly $30 million across seed and Series A rounds, attacks that problem by simulation. Agents are dropped into more than 50 sandboxed environments spanning 14 domains where mistakes carry real consequences, then subjected to simulated prompt-injection attempts and attacks against tool-calling interfaces including the Model Context Protocol. The point is not to prove an agent is safe. It is to find the specific sequences where it is not, in a place where nothing breaks.
The continuous validation piece is arguably more valuable than the one-time test. Agents are not static: a model update, a new tool, or a tweaked system prompt can reopen a hole that was closed last month. Virtue AI re-runs its battery across more than 1,000 risk categories whenever something changes, and produces evidence packages that a compliance team can actually file.
Where This Lands in Fortinet's Platform
Fortinet is positioning the acquisition as a complement to its existing FortiAIGate product and a component of what it calls an AI-native security fabric, spanning networks, endpoints, cloud, applications, and AI deployments. Chief Executive Ken Xie framed the reasoning simply, saying that "security must evolve just as quickly" as AI is changing enterprise computing.
The real-time guardrail layer is the piece most organizations will touch first. It enforces configurable policy across text, images, video, audio, and AI-generated code, with the aim of stopping harmful content, sensitive data, jailbreak attempts, and unsafe generated code before they reach users or downstream systems. Guardrails alone are not a security program, but they are the control point where policy becomes enforceable.
Why the Market Is Consolidating Here
Gartner projects the AI ecosystem security market growing from $2.8 billion in 2026 to $16.4 billion by 2030. That trajectory explains why platform vendors are buying rather than building: the specialist tooling exists, the customers are asking now, and the window to establish a default is short.
It also continues a pattern we have been tracking all year across AI security coverage. CrowdStrike put real money behind the same idea when it offered $100,000 to researchers red-teaming rogue AI agents earlier this month, and more than 40 vendors pooled defensive work when the Open Secure AI Alliance formed under the Linux Foundation in July. Adversarial testing of agents is moving from a research curiosity to a line item.
What to Take Away If You Run Agents
You do not need an acquisition to start. The methodology is public enough to copy in miniature: build a sandbox that mirrors your agent's real tool access, write down the ten actions that would hurt most if the agent took them, and spend an afternoon trying to induce each one. Log what works.
Then automate the ones that worked as regression tests, and re-run them on every model change. That is the durable lesson underneath this deal. Agent security is not a gate you pass once. It is a suite you run forever, and the vendors are now selling the suite because enough organizations have learned that the hard way.
Sources: Fortinet press release — August 17, 2026; SecurityWeek — August 2026; Help Net Security — August 17, 2026.
More Ai Security Stories

Mandiant AI Agents Found 100 Critical Flaws in 2 Days
Google's Mandiant published its AVDH blueprint after the agent pipeline verified 100+ critical vulnerabilities in 48 hours and produced 12 assigned CVEs.

Stealthium Watches the GPU Layer Most Tools Miss
Stealthium launched a security control plane for GPUs and AI accelerators, turning kernel traces and VRAM telemetry into detections for neo-cloud workloads.

OpenAI Model Security Adds Sandboxes and 30-Min Alerts
OpenAI published a new internal security bar: hard sandboxing, activation classifiers on sampled tokens, and a 30-minute alert-or-pause rule.
