What Virtue AI actually governs.
Virtue AI comes out of AI security research, and the product shows it: it attacks agents before they ship and guards their tool calls once they run. What it is built to decide is whether an action is unsafe. Who the action belongs to is a different question.
The product, module by module
The platform is sold as a set of named modules. The agent-specific ones sit under AgentSuite, a blue-team side and a red-team side, with general-purpose guardrails and governance beside them.
- AgentSuite-Bluethe runtime side. ActionGuard applies stateful guardrails to each agent action, judging a tool call in the context of the steps before it so multi-step attacks are caught. MCPGuard scans MCP servers continuously, both their source code and their tool descriptions. A unified agent gateway sits between agents and their MCP tools as one enforcement point.
- Shadow AIendpoint-level discovery for AI tools and agents. A lightweight collector runs on Linux, macOS and Windows, alongside an existing EDR or on its own, and surfaces commercial assistants, self-hosted models, browser extensions, IDE plugins and informal agent pipelines.
- AgentSuite-Red and VirtueRedadversarial testing. A red-teaming agent probes your agent across dozens of sandboxed, production-grade environments under direct and indirect prompt-injection threat models, and reports attack success rates as control evidence.
- VirtueGuard and VirtueGovguard models for text, code, image, audio and video in more than a hundred languages, natural-language policy authoring mapped to over fifty regulatory and industry frameworks, and the compliance reporting around them.
It deploys in the cloud or on-premises, and it supports agents built on the major frameworks plus custom ones through generic wrappers. Virtue AI is now part of Fortinet, which says the acquisition complements its AI gateway and that Virtue AI will enhance its Security Fabric.
Where Virtue AI is strongest
Three of the fifteen rows below go to Virtue AI and four are level. They follow from what the product was built to do: find out how an agent can be broken, and stop the attempt when it happens.
- Adversarial testing before productiona red-teaming agent working through sandboxed environments that mirror real business systems, before the agent under test ever touches one. We govern agents once they run, which is what lets the same policy reach agents nobody tested first.
- Prompt-injection and content-threat detectionpurpose-built guard models across five modalities and more than a hundred languages. We judge the action an agent takes rather than the text it was given, and run alongside whatever inspects that text.
- Ecosystem reachjoining Fortinet's Security Fabric gives the product a wider distribution footprint than ours today.
- Level on four rowsMCP tool governance, with servers scanned and every call guarded; an audit record per action, from tool-call traces and the endpoint collector's operational record; agents built on any framework; and deployment in the cloud or on-premises.
Where Shadow AI stops and ActionGuard starts
ActionGuard's enforcement is real: a tool call that breaks policy is blocked before it fires, and the agent keeps running. The open question is not whether Virtue AI blocks, but where.
The vendor draws the line itself. Shadow AI is the discovery and monitoring layer, a collector on the endpoint, and active blocking lives in ActionGuard on the tool call. An assistant found on a laptop, or an agent running as a browser extension, is inventoried with its host and user; no page documents stopping its next action on that device or in that browser. That is why the moment-of-action row scores a 3 rather than a 5.
Unsafe is not the same as unaccountable
Every verdict in this product answers one question well: is this call an attack, or out of policy? It is a good question, and the stateful view across steps makes the answer better than a call-by-call filter.
A security review asks a second question: whose agent is this, and who answers for what it just did? The collector records host and user context, but no page documents a standing owner assigned to an agent, or an action attributed to one. A perfectly safe action can still be one nobody should have taken, and the verdict about safety cannot tell you who owns it.
Three questions to put to Virtue AI
Virtue AI answers the security questions thoroughly: can this agent be broken, and is this call an attack? Governing an agent asks three more, and the table is organised around them.
- Be at runtimeActionGuard decides as the tool call happens. The test is reach: does the assistant Shadow AI found on a laptop, or the agent living in a browser extension, get that same decision before it acts?
- Know the identityShadow AI records the host and the user context. The test is whether an action resolves to the named person who answers for the agent, rather than to the machine it ran on or whoever was signed in.
- Cover everythingAgentSuite-Red covers the agents someone chose to test, and VirtueGuard covers what it is plugged into. The test is everything else: agents on devices, in browsers, and facing your customers.
Price usually settles the decision, and Virtue AI, now part of Fortinet, publishes neither a price nor a pricing unit. Cost stays unscored here rather than guessed.