Secure AI Conversation, Not Just the Data, with Fortinet
In Fortinet’s presentation at AI Field Day 7, Maggie Wu emphasized how the emergence of AI applications has radically altered the cybersecurity landscape, moving beyond traditional web security into more dynamic, conversation-driven AI interactions. The company’s approach integrates threat intelligence from FortiGuard Labs into their systems, providing real-time insights and protection across network environments. Their AI models, developed and maintained within Fortinet’s infrastructure, are further tailored to customer environments by mapping incoming AI interactions to localized context, ensuring outputs are relevant and secure for specific clients. Fortinet utilizes public LLMs for basic interactions while incorporating customer-specific data locally to avoid unnecessary exposure.
Wu elaborated on a multi-layered strategy to secure not just data, but also the AI-driven conversations themselves. Recognizing that modern AI systems are vulnerable to prompt injection, data leakage, and model poisoning, Fortinet introduced an AI orchestration layer and a set of protections designed to sanitize both AI inputs and outputs. AI infrastructure is continuously scanned for vulnerabilities, and user/environment-based access controls are enforced rigorously. They have also integrated security into their CI/CD pipelines, ensuring that AI models are secure even before deployment. This multi-faceted approach helps prevent security flaws from being exploited during any stage of the AI lifecycle.
Fortinet differentiates its offering from competitors by embedding AI capabilities directly into its existing unified platform rather than creating separate AI products. This integration enables smarter, context-aware automation across Fortinet’s entire ecosystem of security, networking, SOC, and SASE solutions. While optimal performance is achieved within a Fortinet-centric infrastructure, the company also supports multi-vendor environments by offering modular add-ons like FortiAI Assist, which can integrate with third-party SIEM and SOAR platforms. Their AI governance model includes comprehensive tracking and compliance monitoring of LLM interactions, supporting enterprise needs for regulatory adherence and ethical AI use.
Recorded live in Santa Clara, CA as part of AI Field Day 7 on October 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-ai-field-day-7/ or visit https://www.Fortinet.com or https://TechFieldDay.com/events/aifd7/ for more information.
Transcript
You know, with the new, um, AI application, I think the landscape change, right? We're no longer in the traditional way of, um, web application. Maggie, Before you get off the knock discussion mm-hmm.
Um, we talked about it 40 protect, you know, providing, you know, um, 40 labs providing information about malware or things of that nature. How does that play out in the network? Are you, are you analyzing network traffic to understand whether there is malware or, or si cybersecurity threats going on?
Is it, how does that play out with 40 assist? And, you know, it's like, yeah, That's, that's where the, um, I think the integration comes in. So, um, all the information that, or the threat intelligence that we got from the Forti guard lab, right?
Um, they feed into the NOx side of things, right? So they becomes one of the, uh, decision making factors, uh, when it comes to, you know, um, what is the vulnerability and how it impact your network, not anybody's else's network and based on your network environment, right? Um, so I think that's exactly, um, how we operate the 40 guard threat intelligence and the, the, all these, um, IPS signatures gets feed into the management side and management digest all these things and, uh, can provide, you know, kind of policy recommendations, remediation actions, and the things like, So, uh, so this is Dave Graham from ML Commons.
Uh mm-hmm. So one of the, one of the things that I'm, I'm interested in then, and it's been kind of percolated in the back of a few of our brains, is that where is all this data? Where number one, where is all this data?
Mm-hmm. So you're talking about, so I used to work for Veritas and Norton for, or Symantec way back in the day, so we know about delivery of payloads and DAT files and incorporation of things that you've discovered in your labs and whatever. Mm-hmm.
Now, are you constantly retraining, uh, uh, a model somewhere within four labs in order to provide that to the LM? And if you're doing that, then where is this model being run? So if a customer is adopting 40, I is running on Fortinets infrastructure and then being provisioned back down where the customer is interacting with Fortinet directly on a, on a managed service kind of basis, or is it being run local into, uh, a data center somewhere on customer prem is being run on the control plan of hardware?
Mm-hmm. Yeah, just a little bit more explanation around kind of where all the, the locus of and everything is Would Okay. Would be excellent.
Yeah. Yeah. I, I, I registered two part of your question.
I think the first one is where is all this intelligence run and, uh, oh, how do you do it? Yeah. So it's running in our 40 guard lab, and, uh, it's our, we have the machine learning model and quite mature.
We are in the sixth generation of machine learning, and all these intelligent are in our 40 guard cloud. Okay. So, um, all the signatures and the thread intelligence, um, for our 40 gate, you can grab all those signatures real time, or you can schedule them to, to get to your network.
So that's one part of it. In terms of our 40 AI assist, uh, where it runs. So, um, there's two part of it, right?
Uh, we do use the LLM, we do use the public LM for now. Um, so all these, um, you know, kind of, uh, prompt injection and things like that are getting from there. However, um, we, we do have the, um, the, the comp, the, uh, business specific or the, any customer specific, uh, networking environment or the manage environment in mind.
So that's store locally. So when the answers, when the things comes back, we map them into the customer's environment. So that becomes relevant to that specific customer, not the other customers.
Yeah. Yeah. Appreciate it.
Thank you. Okay, thank you. Um, yes, let's move on to AI F 40 ai secure ai.
So this is more about, you know, I'm not, I'm no longer securing the data, you know, um, I'm, you know, not only worrying about data being stolen, but I'm more worried about, you know, the, the application, the, the, the, the AI brain that can talk and think, um, I'm more worried about somebody's, um, listening to the conversation and, uh, you know, um, inevitably still a lot of sensitive data that might AI probably, you know, unknowingly reveal. So this is more about, um, go beyond safeguard your data into safeguard every conversation that you have with ai. So, while we say that, then we quickly, let's see.
You know, this is a simplified version of the web application where you have users, developers, they use credentials to access the application. They have to pass the firewall inspections, they get to the application, and the application will fetch the data. It's very structured data from a very specific, uh, database locations, and you get a very fixed answer because that would not go wrong based on your role and based on the rules and the permission.
So what difference in the new ai, um, world, right? Um, we have these, this new ingredients, key, uh, components added into the picture. First is our, um, AI orchestration layer, which have the embedded, uh, your pre-trained LLM as well as the, like your knowledge base, your company specific training data.
So by adding those in, you basically change the competitor, uh, the, uh, security landscape a lot, right? If you open up your data, your internal data, that means you are creating a new attack path, uh, for the attackers. So they can basically, um, get to your data and poison that therefore, you know, knowing the, uh, you know, corrupting the, um, the AI's very understanding of things.
Um, then you have the, um, ai, uh, orchestration layer. Uh, by having that, you basically are exposed to a lot of prompt injection, um, risks, um, from there. And the whole pipeline also cause, uh, data leakage possibilities or risk.
So, uh, so if you look at that, um, you will say, okay, this is no longer, um, safeguard the data, and you have to safeguard the, the whole dialogue, the whole conversation. So we believe here, you know, in order to protect that, we need to have a multi-layer approach. So of course, we need to secure the access.
We still need to secure the ai, um, the infrastructure that AI live on, but we also need to secure the conversation, and we need to secure the model and the data. So this is how we approach it. Um, so give you a couple of the examples of our 40 AI secure AI capabilities.
So first is more hardening the AI infrastructure. This means that, uh, you have to secure the very environment that you, your AI leave and build. So, uh, with that, we have some key capabilities.
First is we continually scan for vulnerabilities and misconfigurations. So if you have an, um, you know, like a unsecured, uh, cloud storage, or you have a container that have like a, uh, critical vulnerabilities, we block that, um, from that in, uh, you know, kind of a poison your system. And then we also monitor and map identities with access.
So over here in the new AI system, the users are not the only, uh, identities. There's services, there's applications. So we ask them critical questions like, is this data processing microservice, um, be able to retrain my core model?
Right? Of course it can. So we eliminate that, um, excessive privilege for access.
Um, and then also very importantly, um, we integrate directly the security into our, uh, continuous, uh, integration and continuous delivery pipeline. Meaning that, uh, if, uh, a developer wants to, uh, deploy a new AI model which have critical vulnerabilities, we stop them. So we're not only protecting the AI in production, we're also ensure the AI is born securely at the very starting point.
Okay, now coming to the conversation, we secure the conversation. By that we mean that, you know, we, we check the, um, the user input into AI before the AI itself sees it. So we sanitize it, and then when the AI responds, we also check that before the user sees it, right?
So, um, that's just two simple things. And we also put a gate, um, before the AI so that, uh, we can, uh, monitor and stop any malicious, um, traffic, um, that tackle into AI Consulting. Are you, are you checking for data leakage at that point?
Is that what you're looking for? Or Not on this one, but the next one. Yeah, we do check data leakage.
Yeah. What, what is your mechanism for reviewing the input before it goes to the model and the output before it goes back to the user? Like, do you force a portal in the middle?
Like, are, am I not interacting with chat GPT, I'm typing into a Fortinet window? How, how does that work? I think we mainly listen, right?
Um, I think maybe Keith, um, from the technical side, you can help me answer the question. Yeah. This Is actually related to, um, brand new product that we are going to announce.
So AI 40, Yeah. Okay. Something that, yeah, yeah.
Something that at this point, yeah. Maybe just a couple delay later. You will hear this things from, we're not gonna talk about it today.
Yeah. Okay. I thought you were gonna talk about it today.
Unfortunately, That's why we're here. No, it's okay. But you asked a very good question.
This is one of the most, uh, commonly asked, uh, requests for us, and then we are, we are ready. Okay. Okay, great.
So now comes to my last slide is on AI governance. I think when it's come to AI adoption, many of the, uh, CSUITE people are toping their mind is how do I govern the use of ai? So, uh, over here we, you know, not only have tools to monitor the application uses, um, but also track the, the data flow through it.
Um, we log and trial all the interactions with LLM, so that we can see if they meet the company's specific compliance requirement or, or things like that. So with that, uh, I'm finishing up on Actually maybe a clarification on what you asked. So in this world, for the release of new software, are you doing some kind of man in the middle?
Uh, like that's what I'm asking piece here. Yes. I don't think we got that answered Correct.
You said coming soon. Well, But, but now, like, if you're doing, does this, does this all coming Soon still what you're showing on the screen? Or is This today with DLP, This is something we already Yeah, yeah.
So with, from my understanding, uh, we use, uh, DLP, um, data loss prevention and there's mechanisms. For instance, let's say I'm an employee, I'm about to put a prompt that's a no go in. It can auto generate a warning, um, a notification saying I'm about to break compliance or policy.
Um, so there's mechanisms in there from that technology that certainly could act as that middle ground. Um, and, and that's kind of the quick high level, um, overview of it bridge. This is using traditional DOP technology as a stop gate for the, until the bridge into the next set of features.
You said just traditional DOP, not just Well, traditional in the sense that, you know, I could always do this type of monitoring before, um, that's just uniquely applied to, uh, l to, to a prompt now. Yeah. To, yes.
And there's some additional, for instance, we have like, um, some native capabilities that are packaged up with our DLP, um, from, from sandboxing to an IR team and, and a lot of different components. So I would say it brings a little bit more of an advanced element, refreshed element to it, right? But yeah, we're leveraging it in that capacity.
And with ai, and this is, imagine The constraints are based off of the traditional constraints of DLP. So the, the future is more gen ai, I don't wanna use the word agentic 'cause it's, but more AI driven and LLM driven in the future versus, uh, the limitations of DLP. Yes.
I think you are correct. Yeah. I mean, it sounds like a hybrid between, you know, like what you would, as Ray and I have been chatting about this, like LAMA guard, right?
So some of the principles of Lama guard, as you're doing both prompt and response classification, you're looking at in advance of what's going on, what are you injecting into that prompt in order to get a response from the LM you're providing some safeguards around it, which would be specific to your ip, you know, but an extrapolation lama guard was just more of a, a foundational element of stuff. Mm-hmm. It doesn't necessarily apply.
And then you're doing response classification. Well, is this person entitled to do this? Is it breaking the bounds of what I believe that be in place for this particular model or this particular entity based on the conditions, regulatory or otherwise?
Is that Correct? Roughly approximate, yeah. Yeah, That's, that's a great, great depiction.
So one of the things that you spoken about this afternoon, a lot of other companies are doing as well. What do you see yourself as doing different or better than your competition? Um, AI wise?
Yeah. Okay. Um, I think there are a couple of things if you ask me.
Um, one is we are very practical use case driven. So we don't just building technologies for, because it's new technology. Um, the second thing is we have a very solid foundation to build the AI on top, which is our unified, um, fabric, right?
The platform, the, we have, if you think about that, we have networking, we have security, we have soc, we have, you know, sassy and everything. So all these are running on the common OS that we built. So, um, we first have a very good quality data lake, right?
Because all this, all the datas, all the logs are unified. So we don't need to do any conversions and any mappings and et cetera. So they are speaking, basically, they are, the data are speaking the same language, But I can get disadvantage, not advantage.
Mm-hmm. Right? Because you have more dynamic and a multi-vendor foundation, you have to have much better AI to be able to cope for all of the events and situations are happening.
So having this common foundation isn't necessarily an advantage. Yeah. Well, but along those lines.
Mm-hmm. One of the things I've been wondering that might help fear, um, and maybe I'm just not well enough versed, which is fine, I can ask dumb questions, is, uh, I noted you're both, um, you're, you're, you are, uh, presenting about an OP two operation centers, S-O-C-N-O-C, and I don't, I can't tell if 40 AI is platform or service or both. So there's, there's an element to this, to your point, if, if, if it's an operation center I'm engaging with, then there's a certain amount of multi-vendor I can, I, I can pull into this.
Mm-hmm. But if it's the platform itself that I'm gonna operate, then, then I have to deal with that. And I'm not sure, I don't want to be influenced by what your job descriptions are with Fortinet.
So how much of what you're talking about has to do with the way the operation center, Fortinet op at work versus the way the platform and the product that people can also, uh, buy work, which, where, where is, where's the feature dividing line? So, you know, I would say one, we're first we're customer driven, right? So it's, we're, we're not sort of just mushing together.
Like I could go through other Cases. Well, when you're talking about being use case driven, that's what an operation center is Supposed to, to, to highlight mm-hmm. From, from like customers as well, just from feedback across the board.
But, but to highlight a couple things, and to, to be clear, we're not just limited to, um, like Fortinet only and when it comes to kind of the, but, But when you say we, you mean the SOC or the NOC, right? So, So, no, no, no. I'm gonna go beyond that.
Okay. So when we look at 40 AI as a whole, we have 40 ai, that's kind of the, the, the brand, so to speak, then, right? Um, protect is, uh, uh, multiple services and solutions that can make up of it, but it comes with a lot of our products already, right?
40 AI assist, whether it's for the NOC or the soc, N-O-C-S-O-C, right? That is something you're adding on to your existing core technology stack, right? So I might have this centralized data lake, um, a a, um, centralized, you know, log management platform of sorts and analytics or SOAR platform.
And I'm, I'm adding on 40 AI assist for the, the Gen AI and the gen AI capabilities to my technology stack. So those, that's the differentiation kind of between those two, right? If I have, I'm using multiple vendors and I'm so happy to use, let's say I'm using Fortinets, um, security orchestration automation response platform, while that's a mouthful.
Um, and I'm using, uh, four different vendors, one's for my log management. I'm working with, you know, a bunch of other tools, different firewalls. Let's say I can add 40 AI assist on right to my soar, and it's gonna help me across all of the multi-vendor products that I'm using.
So that's one use case example. But let's say I am, you know, we, we do see many customers that are, uh, dominant Fortinet shops, right? Um, and so when we see that, what we're seeing is them using it, leveraging the, um, the, um, interoperability that we've built across our own products, our own platform.
And that's kind of a distinction. It's a little bit more, you know, natively integrated, going through less consoles than you would, uh, uh, with multi-vendor environments. Um, we cater to both.
And then kind of that cutoff is 40 AI assist is really that add-on that's gonna enable agent AI and, uh, uh, capabilities and gen ai, simple add-on. And then, you know, your 40 AI protect, it's, it's a combination of services and subscriptions, um, and, and, and technologies. I think the major difference if you compare us with other vendors is, um, if you look at our AI capabilities, um, it's not a new product or new portfolio or new solution is always embedded in our current solutions.
So it's not like, you know, we, we have to invent or acquire some company to, to, to have this, uh, capabilities. It's whenever we have the SOC system or have the knock, we already have that, but we just use AI as an enabler to make it, you know, smarter, faster, and more efficient. Um, so I think our vision is we foresee that AI will become this enabler across more, um, solutions in our platform, of course, in collaboration with the much larger equal environment.
And that's also our vision, that through the agent AI capabilities, we can talk and communicate and collaborate with this ecosystem on that base. So that's, that's helpful. So Ivan, if I, if, if, if I take your point correctly, if you're already a mix and match shop, this can fit in with it, fit in with that and maybe simplify or unify, simplify through unification some areas of it.
But if you are, if you are more of a single source type style of shop, then there's a, um, a, an opportunity for you here as well. Yeah. It's primarily a fortunate ecosystem play that's where you, the be the greatest benefits.
Uh, I, I, you know, I think it, I don't want to, I wouldn't say just Fortinet ecosystem play because it really, it, it depends on so many variables, right? Like the example I gave with the, with Soar that I could just have Fortinet, SOAR and 40 AI and everything else is, is non Fortinet products and still get just the same benefit. So, you know, the, the, there is an advantage when we talk about consolidation of products and, you know, the, the, the interoperability and, and, and reducing the consoles and those benefits kind of separately, and then AI kind of layer onto that.
Sure. But it's, it's different. It's different strokes depending on, you know, what your objectives are as organizations, your values, your requirements.
I do wanna say though, and I don't want to interrupt the conversation, but I would love to, to show some demos of this. And we only have about 20 minutes left, and I think that it would really help everyone, and I know you've been waiting as well, um, where Keith can kind of walk you through and show you the different components and what they look like, and we can continue the, the, the conversation there if that works.