Skip to main content

folkfox

Skip to main content
Skip to content
Managed Security

MDR Services Just Grew a Second Set of Watchful Eyes

Fortinet has bought an AI red-teaming outfit whose own founders had already left for Meta, and folded what remained straight into the guts of its detection and response stack. The quietest acquisitions are usually the ones worth watching most closely.

Quick answerFortinet acquired Virtue AI to add automated red-teaming and runtime guardrails to FortiAIGate, extending its MDR services into agent monitoring, so agentic AI security becomes a standard line in managed detection contracts, not an add-on.
Section 01

What Fortinet Actually Bought When It Bought Virtue AI#

The founders had already gone hunting new ground at Meta. Fortinet bought the den they left behind, and the traps inside it still worked.
folkfox, on the quiet shape of the Virtue AI deal

On 17 August 2026, Fortinet announced it had acquired Virtue AI, a two-year-old AI safety and security outfit, and folded its technology directly into FortiAIGate, Fortinet's runtime layer for protecting AI systems. Ken Xie, Fortinet's founder and chief executive, put the reasoning plainly: AI is changing enterprise computing fast enough that security has to keep the same pace. SecurityWeek's coverage notes the financial terms went undisclosed, with Fortinet calling the sum immaterial to a company with over half a million customers. Virtue AI itself had raised a comparatively modest $30 million across seed and Series A rounds in 2025, a sum any fox would call a small quarry for a deal this quietly consequential.

The technology being absorbed is not a single product but a stack. Virtue AI's own site describes VirtueRed, an automated red-teaming engine that runs 100+ proprietary attack algorithms across more than 1,000 risk categories, paired with VirtueGuard, a real-time filter that screens text, code, images, audio and video in 100+ languages at sub-10ms latency. Sitting above both is AgentSuite, split into AgentSuite-Red for testing autonomous agents inside sandboxed enterprise scenarios and AgentSuite-Blue for watching those same agents once they are live, complete with tools Virtue AI names MCP Guard, Action Guard and Shadow AI, built to catch an agent quietly wandering off its script.

The founders had already flown the coop#

Here is the wrinkle a search snippet would miss and a fetched page catches. Two months before Fortinet's announcement, on 25 June 2026, Axios reported that Meta had hired three of Virtue AI's founders, Bo Li, Dawn Song and Sanmi Koyejo, straight into Meta Superintelligence Labs, along with several of their colleagues.

So the company Fortinet bought in August was not quite the company those three built. It was the den, the doorways, the traps and the trained sensors they left behind when they went hunting on Meta's ground instead. Fortinet's own announcement makes no mention of the gap; it reads as though the acquisition and the technology arrived as one clean parcel. They did not, and the honest version of this story is better for saying so plainly.

None of that makes the technology less real. It changes what a buyer should actually ask, and that question runs right through the rest of this piece: not just what does the product claim, but who is left to maintain the claim once the product changes hands.

Section 02

AI as Armour, Not Just Another Arrow#

Every AI security story this week could be filed under one of two headings, and it matters which one you reach for first. folkfox's own coverage of Operation ASTERIX this morning was about AI as attack surface: a jailbreak that went shopping for a weaker model the moment a stronger one refused. This story is the mirror image. It is AI as armour, a vendor buying automated red-teaming and runtime guardrails specifically so the AI inside its own customers' networks stops being the thing an attacker goes hunting for.

That distinction is not academic hair-splitting, it is a genuine fork in how a security budget gets spent. Testing whether a model can be tricked and building the plumbing that stops a compromised agent from acting on the trick are different disciplines, done by different teams, sold under different line items. Fortinet buying both at once, inside the same runtime gate, is a bet that enterprise buyers will stop treating them as separate purchases within the year.

A watercolour fox studies a shield that has grown a watchful eye, standing for mdr services gaining an agentic AI layer
A guard that used to only block now also watches, which is a different animal entirely.

Read those five facts together and the shape of the bet gets clearer. Fortinet is not buying a single clever trick, it is buying the plumbing that turns a runtime gate from something that blocks known-bad traffic into something that keeps testing its own assumptions, on a loop, the way a fox never quite stops checking the wind even when the hedgerow looks still.

Section 03

Where MDR Services Meet Agentic AI Security#

Strip away the acquisition news and the underlying category is a familiar one. MDR services, short for managed detection and response, are a subscription: a vendor's analysts watch your endpoints, cloud workloads and now, increasingly, your AI agents, and they act on what they see rather than just alerting you to it. That last clause is the whole point of MDR services. A tool that only alerts leaves the hunting to you; MDR services put a trained team on the trail, day and night, and they are the ones who pull the trigger when something needs stopping.

That is also precisely the gap agentic AI security is opening up. An autonomous agent with access to your email, your code repository or your payment rails is not a passive log line, it is an actor that can take a wrong action in the seconds before a human ever sees the alert. Folding agent monitoring into MDR services, rather than selling it as a bolt-on dashboard, is Fortinet's way of saying agentic AI security needs the same always-on human backstop that endpoint detection has needed for a decade.

It is worth being honest about who else is already circling this same ground. CrowdStrike Managed Detection and Response, sold under the Falcon Complete brand, already markets itself as an agentic MDR service in its own right, combining deterministic automation with what it calls adaptive AI agents and a human-in-the-loop layer, and claims a one-minute median time to contain an incident. Fortinet is not creating a new category so much as making sure it is not left standing outside one that is filling up fast.

The three terms buyers most often confuse, and the one question that actually separates them: who takes the action.
ModelWhat it watchesWho acts on it
SIEMLog and event data you feed it, from anywhere on the networkYour own team, using the SIEM as a search tool
MSSPYour existing tools, managed and monitored under contractThe MSSP escalates to you; you usually approve the response
MDR servicesEndpoints, cloud, identity and increasingly AI agents, via the vendor's own sensorsThe MDR provider's analysts act directly, on your behalf, inside agreed limits

That table is really an answer to two questions people search for constantly and phrase almost identically. Mssp vs mdr comes down to who holds the trigger: an MSSP mostly manages what you already own and defers back to you, while MDR services bring their own sensors and act without waiting for your sign-off on every step. Siem vs mdr is a different fork entirely: a SIEM is a search engine for your own logs, useful only when someone is actively querying it, whereas MDR services are a standing patrol that never stops walking the perimeter.

How big is the MDR market, depending who is counting
Fortune Business Insights
$2.81bn
Precedence Research
$3.92bn
MarketsandMarkets
$6.22bn
Three named analyst firms put the 2026 MDR market between $2.81 billion and $6.22 billion, a spread that says more about how loosely the category is defined than about any single number being wrong.

None of those three firms agree on the exact edges of the category, which is itself the honest lesson: Fortune Business Insights puts 2026 at $2.81 billion growing to $10.43 billion by 2034, Precedence Research puts it at $3.92 billion growing to $13.90 billion by 2035, and MarketsandMarkets puts it at $6.22 billion growing to $17.64 billion by 2031. What every model agrees on is the direction: fast, double-digit annual growth, whichever definition of the category you pick.

Section 04

Automated Red-Teaming Inside Agentic AI Security#

The part of this deal worth slowing down for is not the guardrails, it is the testing that proves the guardrails hold. Manual red-teaming, a human deliberately trying to break a model, does not scale to an enterprise running dozens of agents with dozens of tool permissions each. That is the gap the academic side of agentic AI security has been racing to close all year.

What automated red-teaming is already finding

Risk categories VirtueRed tests for

0+

Across text, image, code, audio and video, per Virtue AI's own product pages.

Sandboxed domains in AgentSuite-Red

14

High-stakes scenarios including tools like Gmail and payment rails.

Attack success rate, zero human code

0%

One Dreadnode agent against Meta's Llama Scout, arXiv 2605.04019.

That 85% figure deserves a second look, because it is the clearest evidence yet that the work has moved from research demonstration to something closer to a production tool. Dheekonda, Pearce and Landers's paper describes an agent built on the Dreadnode SDK that took red-teaming operators from spending weeks hand-crafting attack workflows down to hours, using natural-language goals instead of custom code, and drawing on a library of 45+ adversarial attacks, 450+ transforms and 130+ scorers.

Their case study against Meta's Llama Scout model hit an 85% attack success rate and a maximum severity score, with no human-developed code involved anywhere in the run. That is the underlying research current commercial products like VirtueRed are racing to productise, and it is worth citing precisely because it did not come from a vendor's own marketing page.

CrowdStrike, again, is worth naming here rather than skirted around, because it shows the pattern is not a Fortinet quirk. CrowdStrike Managed Detection and Response describes its own Falcon platform in near-identical language: deterministic automation for the known-safe actions, adaptive AI agents that reason across the environment for the unfamiliar ones, and human analysts validating every decision that actually matters. Two large, otherwise competing vendors converging on the same three-layer architecture in the same year is not a coincidence, it is what a genuinely new SOC pattern looks like while it is still being named.

The honest caveat belongs here too. An 85% attack success rate against one open model in one paper is a strong signal, not a universal law, and Virtue AI's own claimed figures (1,000+ risk categories, sub-10ms latency) come from the vendor itself rather than an independent audit. Buyers should treat both as a starting point for questions, not a finished verdict.

Section 05

What This Means If You Are Evaluating MDR Services Now#

For a folkfox client sitting in a boardroom weighing MDR services proposals this quarter, the practical shift is smaller than the headline suggests but real all the same. Agent monitoring is moving from a separate line item, sold by an AI-safety specialist, into the core MDR services contract, sold by the same vendor already watching your endpoints. That consolidation is convenient. It is also worth pressure-testing before you sign, because a bundled feature is not automatically a mature one.

Ask three things before agentic AI security becomes a checkbox on your renewal. First, is the red-teaming continuous or a one-off certificate, because a model updated last month needs testing against this month's attacks, not last year's. Second, does the guardrail block an unsafe agent action before it executes or only log it afterwards, since the entire value of runtime protection lives in that one word: before. Third, who actually owns the technology two years from now, because this deal is proof that the team who built a capability and the vendor now selling it can be two entirely different sets of people.

The market Fortinet is betting on
Dumbbell chart showing Fortinet's forecast AI ecosystem security market growing from 2.8 billion dollars in 2026 to 16.4 billion dollars in 203020262030AI security market: 2.8 to 16.4AI security market16.4
Fortinet's own forecast puts AI ecosystem security growing nearly six-fold between 2026 and 2030, the scale of shift that makes a $30 million acquisition look cheap rather than cautious.

A near six-fold jump in four years is the kind of gap that explains why a company with over half a million customers bothers with a $30 million acquisition at all: not for Virtue AI's current revenue, which was never the point, but for a seat at a table that is about to get a great deal more crowded. Expect Fortinet's rivals to answer with acquisitions of their own inside the next two quarters, on a similarly quiet Friday, disclosed in a press release nobody outside the trade press reads closely.

If your own MDR services conversation is stalling on exactly this kind of vendor due diligence, that is a scoping problem folkfox helps clients work through directly, alongside the wider content and visibility work that makes sure your own security posture gets found and cited correctly once it is genuinely strong. Our SEO and GEO services cover exactly that citation layer, and our content marketing services turn a genuinely defensible security posture into something buyers and analysts can actually find. For the ransomware pressure that usually forces this decision in the first place, our recent pieces on the Medusa ransomware advisory and the vCenter vulnerability deadline are the practical companions to this one.

Questions

Frequently asked questions#

MDR services, what do they actually include?

MDR services combine a vendor's own detection sensors with a live team of analysts who investigate and act on alerts directly, rather than just flagging them. That typically covers endpoints, cloud workloads, identity signals and, increasingly, the behaviour of AI agents running inside your environment, all monitored around the clock.

MSSP vs MDR, what's the real difference?

An MSSP mostly manages security tools you already own and escalates issues back to your team for a decision. MDR services bring their own sensors and act directly on your behalf inside pre-agreed limits, which is a faster but less hands-on model for the buyer.

SIEM vs MDR, do you need both?

A SIEM is a search and correlation engine for logs you feed it, useful when someone is actively querying it. MDR services are a standing, always-on patrol that acts without waiting to be asked. Many organisations run a SIEM as the data layer underneath an MDR provider's own analysis.

What is agentic AI security, in plain terms?

Agentic AI security covers testing and monitoring for AI systems that can take autonomous actions, like sending emails, editing code or moving money, rather than just answering questions. It includes red-teaming those agents before deployment and runtime guardrails that catch or block an unsafe action while it is happening.

Did the Fortinet deal change what CrowdStrike Managed Detection and Response offers?

Not directly. CrowdStrike Managed Detection and Response already markets its own agentic architecture under the Falcon Complete brand, built independently of this acquisition. The Fortinet and Virtue AI deal is best read as evidence the whole MDR category is converging on the same agent-monitoring pattern, not as a response to any single competitor.

Is Virtue AI still an independent company after the acquisition?

No. Virtue AI's technology and remaining team are now part of Fortinet, folded into its FortiAIGate product. Three of its four named founders, Bo Li, Dawn Song and Sanmi Koyejo, had already left for Meta Superintelligence Labs two months before the acquisition was announced.

The trade press reads the deal the same way: ITPro frames it as Fortinet buying AI-security engineering capacity it could not hire at speed.

Keep reading

Read more on this topic#

Ready to make your security posture findable, not just defensible?

folkfox helps regulated and technical brands turn genuine security work into content buyers, analysts and AI engines actually cite, alongside the practical marketing that gets MDR services conversations started.