Intelligence

Fortinet Bought an AI Security Company. Look at Where It Puts the Control.

Everyone is reading the Fortinet acquisition of Virtue AI as consolidation in the AI security market. The line I keep returning to is much smaller than the deal. Fortinet describes one of the acquired capabilities as blocking malicious tool calls before they act. That is a statement about where the control sits.

Event analysed: . This analysis was published on 17 August 2026.

What did Fortinet acquire in Virtue AI, and what does it mean to block an agent tool call before it executes?

On 17 August 2026, Fortinet announced the acquisition of Virtue AI, which it described as an innovator in AI runtime protection, automated AI validation, and security for autonomous AI systems. Financial terms were not disclosed, and Fortinet stated the consideration was immaterial to its business. Virtue AI's public material describes four product areas: red teaming for agentic systems, agent runtime protection, continuous automated testing of models, and real time guardrails across text, images, video, audio and generated code. The capability that matters for the agent security question is the one Fortinet lists as agent protection, governance, and visibility, which it says provides visibility into agents and AI tools, discovers unsanctioned agents, scans Model Context Protocol tools and source code for hidden risks, monitors agent behavior, and blocks malicious tool calls before they act. Virtue AI describes the same function on its own site as Action Guard, which monitors agent behavior as it happens and blocks malicious tool calls before they fire. Blocking a tool call before execution means the decision is made at the point where the agent is about to invoke a tool, rather than after the resulting action has already changed something. That is a different control location from detection and response, which observes activity that has already happened.

Fortinet announced on 17 August 2026 that it had acquired Virtue AI. The press release calls Virtue AI an innovator in AI runtime protection, automated AI validation, and security for autonomous AI systems, and positions the deal inside Fortinet's broader strategy for securing what it calls the agentic enterprise. Financial terms were not disclosed. Fortinet stated that the consideration paid was immaterial to its business.

That is the whole news event. The part I find worth writing down is one clause inside the capability list.

The exact language that matters

Under the heading of agent protection, governance, and visibility, Fortinet writes that the technology "provides full visibility into agents and AI tools running in their environment, discovers unsanctioned AI applications and agents, scans MCP tools and source code for hidden risks, monitors agent behavior, and blocks malicious tool calls before they act."

Virtue AI describes the same capability on its own site, under a product named Action Guard, as the ability to "monitor agent behavior as it happens and block malicious tool calls before they fire." So this is not language a buyer invented to dress up an acquisition. It is language the acquired company was already using to describe a shipping product area, alongside scanning of Model Context Protocol tools and runtime observability of agent trajectories.

What is verified. The acquisition announcement, its date, the description of Virtue AI, the capability list, and the phrase about blocking malicious tool calls before they act all come from Fortinet's own release. The matching product description comes from Virtue AI's own public material. Everything after this point is interpretation, and it is labelled as such.

Why the location of the control is the story

Most of enterprise security is organised around a timeline that starts when something happens. Traffic is inspected, telemetry is collected, behaviour is scored, alerts are raised, responses are triggered. Even the fastest of those controls is answering a question about activity that is already under way.

Agent security keeps pushing toward a different question. An agent does not merely produce traffic. It decides to call a tool, and that tool call can move money, delete data, change infrastructure, or send something irreversible. Once the call executes, the consequence exists. Detection afterwards tells you what happened. It does not restore the state.

So when a vendor of Fortinet's size describes agent protection in terms of a decision at the tool call, that is a signal about where the industry believes the useful control point sits. Not at the prompt. Not in the log. At the invocation.

What remains unknown

Quite a lot, and it is worth being honest about it.

The announcement does not say how a tool call is judged malicious, what latency the decision adds in production, what happens when the judgement is wrong in either direction, or how the control behaves when an agent reaches a consequential action that is perfectly legitimate in isolation. It does not describe coverage: which frameworks, which tools, which protocols, which deployment shapes. It does not describe what a human does when something is stopped. Virtue AI's public material claims real time protection under ten milliseconds for its guardrail models, which is a performance claim about guardrails rather than a description of how an agent action decision is made.

There is also a definitional gap that no press release resolves. Blocking a malicious tool call assumes malice can be recognised. A large share of the agent incidents worth worrying about involve no malice at all. An agent pursuing its assigned goal, taking a technically permitted action, against a resource nobody thought to place out of scope, produces the same consequence as an attack and looks nothing like one.

The open question

If the market is converging on the idea that agent security means deciding before a tool call executes, then the next argument is not about whether to intervene. It is about what the decision is actually evaluating. A control that only recognises malicious calls covers one class of failure. A control that evaluates whether a consequential action is authorised at all covers a different one.

Which of those two things do you think enterprises will end up buying, once agents are routinely acting on systems where the wrong call cannot be undone?

For the underlying distinction, see why authority has to be answered at the moment of execution and why instructions are not authorization.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[1]
[2]
Virtue AI platform overview
Virtue AI · 17 August 2026 · Company announcement
[3]
Fortinet expands AI security portfolio with Virtue AI acquisition
Help Net Security · 17 August 2026 · Journalism

Related Intelligence

All Intelligence Records →