Empower Innovation with AI Secured by Fortinet Fabric
In his presentation at AI Field Day 7, Max Zeumer from Fortinet discussed how the rapid adoption of generative AI has transformed the threat landscape and the imperative for organizations to secure their AI usage. He began by highlighting the explosive growth of generative AI compared to past technologies, stressing that enterprises must adapt quickly to its integration. While some organizations are implementing AI in a structured way with governance and compliance, most are still in the early stages and lack visibility and control, which introduces significant risk. Zeumer noted that as AI progresses from reactive prompt-based tools to agentic and autonomous systems, enterprises face mounting challenges to secure data, manage usage, and maintain compliance.
Zeumer emphasized that quickly evolving AI tools also present new vulnerabilities in the cybersecurity space. Threat actors have begun using AI to create convincing phishing attacks, social engineering campaigns, and malware, often lowering the technical barrier for carrying out sophisticated cyberattacks. In addition, internal risks were discussed, such as employees unknowingly feeding sensitive company data into public AI platforms. This lack of governance can lead to data leakage and regulatory breaches. Fortinet sees a growing need for enterprises to monitor the various applications of AI within their organizations, understand who is using it, how, and what data is being processed, especially as adversaries increasingly employ AI in weaponized forms.
To address these emerging concerns, Fortinet has developed a comprehensive AI-integrated cybersecurity framework called Fortinet Security Fabric, powered by its proprietary AI platform, FortiAI. This system is structured around three main pillars—FortiAI Protect, Assist, and Secure AI—covering threat detection and prevention, operational augmentation, and safeguarding AI systems themselves. FortiGuard Labs plays a fundamental role by continuously collecting sophisticated threat intelligence and feeding it into these systems. This allows customers to receive accurate, real-time insights, manage risk from generative AI applications, and set governance rules. Fortinet’s unified platform and deep AI capabilities, backed by over 500 patents and years of innovation, position it to help enterprises adopt AI securely while maintaining performance and compliance.
Recorded live in Santa Clara, CA as part of AI Field Day 7 on October 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-ai-field-day-7/ or visit https://www.Fortinet.com or https://TechFieldDay.com/events/aifd7/ for more information.
Transcript
My name's Max Soyer. I'm the director of product marketing for the Fortinet SOC platform. Um, today I'm joined by a few of my colleagues, and we're gonna walk through, initially set the stage and share Fortinets journey around ai, how we're helping our customers, how they're using it, how we frame it, and then we'll dig into, um, specific use cases, demos, and open the floor for, uh, any questions and you can stop and ask, of course, at any point in time.
With that said, uh, you know, I'd like to jump in and, and just kind of start kicking off, um, the evolution. Um, the time it took for mobile phones to reach 1 billion users was 19 years. When we look at the internet 14 years and then five years with a smartphone.
And when it comes to ai, especially in this case, gen ai, that was under a year approximately to reach 1 billion users, that is fast because we have to adapt to this innovation, right? Especially in the security world. How do we know that this AI is safe, but how do we keep it safe?
How do we correctly implement it? And instead of taking years to develop these frameworks, these strategies, these best practices, it's turned to months where we have to quickly adapt and every organization has to. And in order to, to kind of also set the stage here, I wanted to walk through just briefly what we're seeing in terms of the enterprise AI journey.
Um, it typically, you know, most enterprises are pretty early in their stage of AI adoption, but the vast majority are using generative ai. Um, you know, prompt driven, reactive. I have this problem, I have this question, you know, let me get a response.
And, you know, they're using it, uh, some ways structured, organized, they've implemented, you know, um, with governing policies and, and clear transparency. That's a perfect world. But the majority, unfortunately, um, it's kind of like the wild, wild west, right?
They're, they have no real compliance in place for it. They, they're probably not aware of all the different gen AI apps that are being utilized, um, across the organization. Um, and, you know, that certainly can, you know, increase risk.
Um, and that's just a byproduct of how rapidly, uh, AI's been adopted. Um, now we are seeing, of course, this move to agentic AI for autonomous capabilities, right? The, the, the autonomous reasoning where I can go from being, you know, reactive to more proactive, 'cause I'm passing the task or the larger set of tasks, the goal to ai, um, and offloading and augmenting that.
There are a few, uh, you know, uh, folks that are focused on this and, and really starting to kind of push towards that direction. Um, but they're not fully there yet. And then we have our, our, the, the private, uh, model, right?
Um, a privately hosted LLM. Um, and this typically we're seeing either really large enterprise customers or telcos kind of move towards this direction, um, very early stages. But I have heard directly from customers, you know, that this is something they're doing.
And one of their big priorities here is to figure out how they can integrate AI across their stack, right on-prem. And also for compliance purposes and security purposes. And these are a couple of the areas that we've seen it in, but just as fast as the AI has been utilized for good and has been, you know, adopted by organizations, it has created, uh, quite a number of, um, new expanded, uh, attack surface components, right?
And the way it's done, this is first just like we're leveraging the innovation of ai. So our threat actors, we optimize our operations as the good guys. We're looking at where can we improve, where can we automate, where can we do this process and, and do it fast, quick, efficient at scale.
They're turning around and weaponizing ai, they're launching these attacks at scale and the way that they're doing it extremely effectively today. Sure, we know that there, there's some that are using it to build out, uh, pretty complex attacks. But for the most part, it starts with creating extremely compelling phishing copy, um, you know, copy for, uh, pitches around social engineering tactics.
Um, and they're using this to kind of launch and scale these attacks really, really fast, creating a beautiful website. And, and they're able to kind of lower that barrier to entry, um, is something we're seeing where I don't need to be as much of an expert, um, in terms of, of, of being a threat actor as perhaps I once was. 'cause now I have the assistance.
And for the folks that are true, um, you know, uh, threat actors that have that experience, they're using this to augment an offload just like we are. In addition to that, this creates more concern around the AI supply chain, uh, vulnerabilities. Uh, of course, internally, many employees unknowingly misuse AI because they're not informed.
We're seeing that quite often where you have, uh, proprietary information, um, injected into a public LLM, right? And, um, not only that could break your company's compliance, but also, uh, that information, uh, could do a lot worse. It can break regulations depending on your organization.
Um, and, and this also not only makes the attacks more dynamic, but you gotta remember the area that you have to continuously monitor and search through when it comes to threats, um, is very broad. And as we increase applications, as we increase devices, as we increase the number of users, You know, there's been a lot of talk about AI weaponization. Are you actually seeing some of this in the field?
I mean, from the orine perspective, or, Yeah, great question. So, you know, first, when it comes to weaponization, the first thing we're seeing is like they're utilizing it to enhance their existing tactics. So that's at its foundation.
Now, many folks will say, oh, we're seeing a AI being used to generate, you know, all these new malware strains that have, we've never seen before. And, and truthfully, we're not seeing a ton of that. Have we seen it?
Yes, to an extent, but at the foundation, just like, you know, we optimize these cyber gangs, they're working together, they're collaborating, and then they're using the AI to do what they're doing more efficiently and at scale. So it's typically what what we're seeing, uh, predominantly. But, um, yeah, unfortunately, we, we, we have seen some usage to help them develop some of these, these, uh, you know, different malwares and strains.
So Frederick Van Hern from, uh, hyphens Consulting, so ignoring AI for a little bit, um, I mean, historically a lot of the, uh, hacking is actually coming from the inside, you know, where somebody's being compromised. Um, so is, is that also an angle you're approaching, is how can you protect enterprises from the inside knowing that somebody had a level of trust and that trust is compromised? You know, thank you for asking that question because it's, it goes perfectly into our next topic.
Um, yes. You know, ultimately we see quite a number of organizations deal with like the misuse of AI itself, right? And it's not necessarily the threat actor coming in and, and using that ai, for instance, like in, in your example, it's because somebody has made a mistake, right?
But they still leverage the AI to create, like really convincing scripts to social engineer, right? Um, we're seeing, um, folks un the organization not have visibility into the applications that are being utilized. And so that's where you risk that insider information, that proprietary information from, you know, leaking out data leakage.
Um, and that is a significant risk, but we're also seeing a lot of, um, deep fakes, right? Um, and, and vishing, all these components still leverage ai, but even if you, you put that aside, that tends to be the, the focus that just helps 'em do it a lot better. Does that answer the question?
I Does. Thank you. Okay.
Um, So this brings a lot of, uh, considerations, uh, top of mind, right? One, um, as I'm adopting ai, I need to have visibility into it. Who's using it in my organization, right?
What are they using? Um, how are they using it? What are they putting in there?
Can I control anything around that? Um, how do I govern, right? Um, these are all things, you know, how do I ensure that my data remains private and secure, um, and, and, and control the overall usage of the ai, put these guidelines in, but also have, you know, trust and transparency within our models and stay compliant not only in in my organization framework, but also with regulation.
Lastly, does my, does the AI integrate? Does it integrate with other ai or does it integrate across the technologies that I'm using to help bolster my usage of those technologies? Um, and these are kind of the, the core areas that we're seeing, you know, customers starting to really debate, um, and, and take into consideration.
With that said, I would say the majority that are taking these, these foundational areas into consideration would be your, your enterprise, your larger enterprise, um, of course, um, service providers and telcos. Um, but the, the, the organizations that are a little bit smaller don't, um, or they're not quite there yet. They're just doing, uh, components.
And, you know, when it comes to Fortinet, for those that are not as familiar with Fortinet, I wanted to take a quick second and just lay the stage of our entire platform. The reason being is it will give you a good understanding of where our, our AI sits and how it works and is embedded across our platform. So when it comes to Fortinet, we, we have one of the, the most comprehensive cybersecurity platform in the industry, um, in which we have one operating system for both networking and security.
And we tie this all together through something we call our security fabric. It's, it's the glue. It's what brings all of our solutions and, and, and unifies the telemetry, um, as well as having, um, the ability to kind of switch through them very easily.
Um, and so it, we have our first pillar of secure networking, and what this really focuses on is, is converging the security, the networking across every vi uh, device and edge, all the way to unified SSE, where we can secure users across any cloud, any application, and secu AI driven security operations, which is AI driven security operations for faster detection around those threats, investigation and response. And again, all tied together with that common operating system, uh, single operating system, the security fabric. And within that, we have our, uh, threat intelligence feed into it, our, our 40 ai, our AI component distributed throughout it, and, um, our vast ecosystem.
And this makes it really easy to adopt, especially if you're leaning towards a consolidation effort and to keep that in mind. Now, let's talk about our ai, which we call 40 ai. That's, that's the, that the, the brand of our ai.
And let's talk about its role within the security fabric, because we have one fabric and it's amplified by ai. What's phenomenal with Fortinet that I love, I've been with the company for, uh, six years, and I've seen a lot of innovation, and I've seen that even over the last 15 years. Um, they've been innovating around AI and, and powering over 40 solutions with it, which is incredible, tightly integrated together.
It's also here at Fortinet, we're the nu number one patent inventor in AI and have well over 500 patents when it again comes to security and ai. We have our 40 ai, which represents all ai, and we break it up into three distinct buckets. These three buckets are 40 AI Protect, um, which is to protect against your, your AI threats, 40 AI assist that's gonna assist you, uh, with your operations and help augment.
And then, uh, 40 ai, secure ai that's all about securing your LLMs and, and your AI systems. And basically this is, um, really in an infinite loop where we have security for AI and AI for security. So let's talk about 40 AI Protect, um, you know, when it comes to 40 AI Protect, what do customers care about?
Because we've maed our framework around the customer's voice. I speak with so many customers every single day as well as our partners, and of course, many, many folks. And they want to have this accurate analysis where they can boost the efficiency of their threat detection and how accurate they are because they don't have the time to potentially detect a threat that may be a false positive.
It may be nothing. I just wasted, you know, hours and hours investigating something we detected and it was meaningless. I don't have the time for that.
I need something that's accurate. So what do I need for that? I need threat intelligence, very deep threat intelligence that's accurate.
And, um, that helps provide some of that AI to detect these AI driven threats that we're talking about a little bit ago, right? To keep pace with that. Um, in addition to that, I need to have visibility into the Gen ai, right?
And also understand the risk of what Gen AI is being utilized across my organization. Um, so I can enable safe usage and prevent, you know, potential threats, potential leaks, and having control over these applications and managing and mitigating that risk. We power, um, 40 AI Protect with Forti Guard Labs, AI powered security services.
Now, Forti Guard Labs for context is our threat intelligence apparatus. It consists of over a thousand threat hunters, threat researchers, data scientists, I mean really, really smart folks that are constantly scouring the world for emerging threats, and they're leveraging the telemetry of our threat intelligence. We have, uh, hundreds and hundreds of partners that we share this intelligence with.
Um, and together we have over 500 million sensors deployed across the globe and hundreds of AI and ML features that help us sift through all this information and enable that base of 40 AI Protect. Um, and, and this will help organizations be able to kind of first pull up those threats, those AI driven threats quickly as they emerge and be able to put them out faster because we're giving them all the tools that they need. And on the backend, we're leveraging our own technologies to quickly deliver the information.
Um, and sort Of like in the old days, uh, malware modeling and stuff like that, you get new malware, they'd release a new database with a, with a malware update. Is that what you're talking about here? When it comes to, so when it comes to For Guard Labs?
For Guard Labs, yeah, to an extent, that's part of it. And then we go up and beyond that. So there's the outbreak detections, we have IOCs, um, but in addition to that, we have all these other services, whether they're expert managed services or subscriptions.
And what's really cool, especially with our expert managed ones like our sock as a service, what I love is that team that's using our own technologies and threat intelligence, they're also shipping back that information and sharing those best practices and the content that they built for our so, um, back into Forte Guard. And so it, it's not just merely here's some, some detection rules, right? Um, it's very, very comprehensive.
And then we're also using that to help. I mean, that's the foundation of where we started, um, developing a lot of our API and ml, right? To, to be able to quickly and accurately sift through this intelligence, make that correlations for the customers, and provide the best practices as well as content.
Um, yeah. Okay. Um, and, and, and so for To Guard Labs is again, just one component of 40 AI Protect, but it's really a, a core part.
Um, it's a series of, of solutions and services that together kind of form it. And now we can talk a little bit about how organizations are getting better visibility using, um, our, uh, for D AI Protect. Um, ultimately, like I said earlier, I have all these applications running.
I need to know what's going on. We can give you that full visibility into what's being utilized across your Gen ai. Um, but we can go a step further too, what applications they're using, how long those sessions are, what the risk of those AI applications might be, um, and of course who, who's using it.
And then we can take that information to help apply guardrails, especially around implementation, um, and helping you protect your organization to be preventative and to adjust the policies and, um, that you may or may not in place.