HomeMalware & ThreatsFortinet Acquires Virtue AI for Enhanced Agent and Model Runtime Controls

Fortinet Acquires Virtue AI for Enhanced Agent and Model Runtime Controls

Published on

spot_img

Artificial Intelligence & Machine Learning,
Next-Generation Technologies & Secure Development,
The Future of AI & Cybersecurity

Acquisition Adds Offensive and Defensive Testing for Agents and Models

Fortinet Buys Virtue AI for Agent and Model Runtime Controls
Image: Shutterstock

In a significant move for the network security landscape, Fortinet, a leading provider of network security solutions, has announced its acquisition of Virtue AI, a platform designed for the protection of artificial intelligence agents and models. This acquisition aims to enhance security measures during runtime, thereby ensuring robust governance of autonomous systems. The integration of Virtue AI’s technology is expected to bolster Fortinet’s existing offerings, particularly the FortiAIGate solution, thereby extending its capabilities in monitoring and controlling AI communications, agent-driven traffic, and various workflows.

Anthony James, Fortinet’s Executive Vice President of Product Marketing, elaborated on the acquisition’s significance, noting that the incorporation of Virtue AI will extend critical tests and controls beyond conventional boundaries. Specifically, he pointed out that the technology aims to prevent cases where employees might inadvertently reveal sensitive information within large language model (LLM) prompts. By leveraging virtue AI’s expertise, Fortinet aims to address the pressing needs of enterprises deploying AI technologies.

James emphasized Virtue AI’s comprehensive approach, which scrutinizes the behavior of both AI agents and the underlying models. According to him, “Virtue is looking at everything inside the AI infrastructure,” ensuring that both agents and models remain compliant with established policies. This meticulous monitoring is vital in the rapidly evolving AI ecosystem, where nuances and shifts in behavior can pose significant risks to security and compliance.

Founded in 2024, Virtue AI was established by a team of esteemed professors from eminent universities such as Stanford, UC Berkeley, and the University of Illinois Urbana-Champaign. The company initially employed approximately 30 individuals, most of whom are transitioning to Meta’s Superintelligence Labs following the acquisition. However, the core technology developed by Virtue AI is now under Fortinet’s jurisdiction, marking a pivotal shift in the landscape of AI-related security provisions.

Fortinet’s acquisition introduces an innovative trust layer specifically designed for AI applications and agents. This framework encompasses four critical functions, merging both offensive and defensive testing capabilities tailored for agents and models. The red-team and blue-team functionalities assist in evaluating various aspects of autonomous agents that interface with LLMs. An illustrative example provided by James highlights an agent capable of autonomously retrieving and analyzing competitive financial data on a daily basis, functioning seamlessly with the chosen LLM.

However, security risks loom when these agents interact with unauthorized sources or become targets of malicious tactics, such as prompt injection attacks. To counteract these vulnerabilities, Virtue AI’s offensive security techniques, branded as AgentSuite-Red, place these internal tools within sandboxed simulation environments, rigorously stress-testing them against real attack scenarios.

This innovative approach diverges from standard benchmarking methodologies employed by industry leaders like Anthropic and OpenAI. Rather than merely executing an AI model within a predefined infrastructure, Virtue AI’s strategy incorporates pre-programmed tests within the sandbox. This allows organizations to evaluate the agent’s actions before direct communication with pivotal services, such as Google Workspace, ensuring that unexpected behaviors are revealed and mitigated prior to deployment.

In conjunction with that, the AgentSuite-Blue functionality evaluates agents for compliance, ensuring that they adhere strictly to the Model Context Protocol and predefined policy scopes. This is crucial for businesses that require assurances regarding the security of their operations. In practical terms, this means that if an agent programmed to interact with specific services unexpectedly targets unauthorized endpoints, the system can halt its operation and investigate the breach.

Moreover, red- and blue-team testing techniques, dubbed VirtueRed and VirtueGuard, are set to enhance the security of both commercial models and company-specific LLMs. James remarked that many enterprises have opted to deploy their LLMs internally for various reasons, including cost management and operational governance. Given this shift, stakeholders have become increasingly concerned with the security integrity of these models, particularly when they are trained on proprietary data.

The tests and policy safeguards introduced are meticulously designed to ensure that deployed models yield appropriate and secure outputs. For instance, a corporate model should not inadvertently disseminate sensitive information or display inappropriate content. As Fortinet prepares to integrate this advanced technology into its FortiAIGate solution suite, it envisions providing comprehensive protection surrounding communications, models, agent workflows, and other essential service components. Although a specific timeline for this integration remains undisclosed, Fortinet is clearly charting a path toward fortified AI security.

The acquisition also sees several key Virtue AI personnel, including one of its co-founders, transitioning to Fortinet. It’s paramount to note that while Meta has absorbed a significant portion of the talent from Virtue AI, Fortinet’s acquisition focuses primarily on leveraging the startup’s groundbreaking technology, which has the potential to reshape the AI security landscape. Financial specifics regarding this transaction have not been disclosed at this time, but the strategic implications of Fortinet’s maneuver are likely to reverberate throughout the cybersecurity industry.

Source link

Latest articles

Perplexity Establishes Guardrails to Control Rogue AI Agents

Open-Source Numbat Blocks Agent Actions That Violate Enterprise Security Policies In an era where artificial...

Enterprise Applications Have 4.31 Times More Critical and High Vulnerabilities

The Growing Challenge of Vulnerabilities in AI-Driven Software Development In a recent analysis conducted by...

Critical MLflow SSRF Vulnerability Exploited in the Wild

Security Flaw Exposed in MLflow: Urgent Response Required A significant security vulnerability, identified as CVE-2026-64849,...

Hacker Claims Millions of Records Stolen from Azure Tenants

A significant cybersecurity incident has emerged, involving a threat actor who claims to have...

More like this

Perplexity Establishes Guardrails to Control Rogue AI Agents

Open-Source Numbat Blocks Agent Actions That Violate Enterprise Security Policies In an era where artificial...

Enterprise Applications Have 4.31 Times More Critical and High Vulnerabilities

The Growing Challenge of Vulnerabilities in AI-Driven Software Development In a recent analysis conducted by...

Critical MLflow SSRF Vulnerability Exploited in the Wild

Security Flaw Exposed in MLflow: Urgent Response Required A significant security vulnerability, identified as CVE-2026-64849,...