# Fortinet Buys Virtue AI to Hunt Vulnerabilities in AI Agents Before Hackers Do

> Source: <https://startupfortune.com/fortinet-buys-virtue-ai-to-hunt-vulnerabilities-in-ai-agents-before-hackers-do/>
> Published: 2026-08-21 01:58:54+00:00

*Fortinet has bought Virtue AI because AI agents are starting to behave like users, tools, and targets at the same time. If you let agents act inside your systems, you need security that watches what they do, not just what they say.*

Fortinet announced on August 17, 2026 that it had acquired Virtue AI, a startup built to test and protect AI agents before attackers get a clean shot at them. Terms weren't disclosed. Fortinet said the amount paid was immaterial to its business, which tells you the point of the deal. This wasn't a revenue grab. It was a capabilities grab.

Virtue AI raised $30 million in combined seed and Series A funding in April 2025, Axios reported at the time, with Lightspeed Venture Partners and Walden Catalyst Ventures leading the financing. The company was founded by Bo Li, Dawn Song, Carlos Guestrin, and Sanmi Koyejo, a group with real academic weight in AI safety and security. That matters here because agent security is still full of vague claims. Virtue AI at least comes with named products, named founders, and a problem you can describe without squinting.

Fortinet's own release says Virtue AI tests autonomous agents across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and Model Context Protocol attacks against leading agent frameworks. MCP is the connective tissue many agents use to reach outside tools and data. If an agent can call a database, open a ticket, send an email, or read from a shared drive, that connection becomes part of the attack surface.

That's the issue.

[Xpeng Beats Tesla's Margins While Racing to Build Robots and Robotaxis](https://startupfortune.com/xpeng-beats-teslas-margins-while-racing-to-build-robots-and-robotaxis/)

Xpeng's first-quarter 2026 gross margin hit 20.6%, ahead of Tesla's automotive margin, even as revenue fell and the company posted a loss. Deliveries jumped 65% in the second quarter on the strength of its new GX SUV, and CEO He Xiaopeng is now pushing in-house Turing AI chips into a robotaxi fleet and a humanoid robot both targeted for mass... - [how to beat Tesla's profit margins in automotive](https://startupfortune.com/xpeng-beats-teslas-margins-while-racing-to-build-robots-and-robotaxis/) - [Chinese EV maker building humanoid robots and robotaxis](https://startupfortune.com/xpeng-beats-teslas-margins-while-racing-to-build-robots-and-robotaxis/)

Traditional cybersecurity was built to watch networks, endpoints, applications, and users. An AI agent breaks that neat map. It can read a document, weigh a request, decide to call a tool, and take an action without a person clicking a button. If an attacker hides a malicious instruction inside a webpage, email, document, or connected data source, the agent may treat that instruction as part of the job. You don't need a stolen password if the agent does the work for you.

## What Fortinet Is Buying

Virtue AI's platform doesn't only simulate attacks. MSSP Alert reported that the technology also discovers unsanctioned AI applications and agents, scans MCP tools and source code for hidden risks, monitors agent behavior, and blocks malicious tool calls. That's a more practical package than another dashboard that tells security teams what went wrong after the damage is done.

Fortinet already had FortiAIGate for this. Now it's folding Virtue AI's capabilities into that broader Security for AI strategy, the product it had already positioned around large language models, prompt injection, data leakage, model poisoning, and MCP servers. The acquisition extends that work from model protection into the messier world of agents, where the risk sits in the action the system takes, not only in the text it produces.

Shadow AI is the part companies should worry about first. Employees don't wait for a security review before trying a coding agent or a browser agent - anything that promises to save an hour. Developers don't always wait either. By the time a security team asks what agents are running, some of them may already have access to internal documents, ticketing systems, cloud tools, or customer data. Visibility isn't glamorous. It's the first thing you need.

## The Race Is Already Underway

Fortinet isn't the only large security vendor chasing this gap. CrowdStrike announced AI detection and response work in March 2026 for securing AI agents and governing shadow AI across endpoints, SaaS, and cloud. Palo Alto Networks launched Prisma AIRS 3.0 the same month, pitching it around discovery, risk assessment, runtime security, and agentic governance. The language varies. The market is converging on the same fear: agents are being plugged into company systems faster than the controls around them are being built.

Frankly, that fear is well placed. A chatbot that says the wrong thing is a problem. An agent that calls the wrong tool can become an incident. The difference is action, and action is what makes agent security a real buying category rather than another AI label pasted onto old software.

Fortinet didn't say when Virtue AI's technology will be fully live inside FortiAIGate. It also didn't disclose Virtue AI's customer count or revenue - or what it paid. Keep those gaps in view. Acquisitions like this often sound complete on announcement day, then take months of integration before customers can actually buy and use the combined product in a clean way.

[Cerebras Unveils CS-4 Chip It Claims Is 30 Times Faster Than Nvidia GPUs](https://startupfortune.com/cerebras-unveils-cs-4-chip-it-claims-is-30-times-faster-than-nvidia-gpus/)

Cerebras launched its CS-4 rack-scale AI system on August 18, claiming up to 30 times faster inference than Nvidia GPUs by fusing three wafer-scale chips into one rack. The launch lands just as rival Groq pivots away from its own chips into renting Nvidia GPU capacity, sharpening the divide over how to win the AI inference speed race. - [Cerebras CS-4 chip performance compared to Nvidia GPUs](https://startupfortune.com/cerebras-unveils-cs-4-chip-it-claims-is-30-times-faster-than-nvidia-gpus/) - [AI inference speed improvements with Cerebras hardware](https://startupfortune.com/cerebras-unveils-cs-4-chip-it-claims-is-30-times-faster-than-nvidia-gpus/)

Still, the direction is clear. Fortinet sells firewalls, endpoint tools, SASE products, and security operations software to companies that already trust it with traditional infrastructure. Now it wants to be the vendor that tells those same companies what their AI agents are allowed to do. If you're deploying agents inside real workflows, you can't treat them as clever assistants floating outside the security model. They are becoming part of the system. Fortinet just bought accordingly.

**Also read:** [NSA and CISA Warn Hackers Are Using AI to Scan Siemens Plant Controllers](https://startupfortune.com/nsa-and-cisa-warn-hackers-are-using-ai-to-scan-siemens-plant-controllers/) • [Micro1 Rockets From $7 Million to $300 Million in Revenue in a Single Year](https://startupfortune.com/micro1-rockets-from-7-million-to-300-million-in-revenue-in-a-single-year/) • [Xpeng Beats Tesla's Margins While Racing to Build Robots and Robotaxis](https://startupfortune.com/xpeng-beats-teslas-margins-while-racing-to-build-robots-and-robotaxis/)
