Security Using AI with Fortinet
At AI Field Day 7, Keith Choi from Fortinet presented an overview of Fortinet’s AI strategy and portfolio, emphasizing the integration of AI within cybersecurity solutions. He explained that the increasing adoption of AI in enterprises is driven by the need for efficiency and innovation, and Fortinet has developed a layered approach categorized into three buckets: Protect AI, Secure AI, and AI-Assisted Operations. These categories are designed to address different aspects of AI-related security, from defending against AI-driven threats, to securing AI systems themselves, and enhancing operational efficiency through AI-powered tools like SOC and NOC support.
Choi detailed various solutions underpinning Fortinet’s AI capabilities. For example, FortiGate, the company’s next-generation firewall, now includes controls for generative AI applications, allowing administrators to manage access and prevent data loss. Meanwhile, FortiNDR provides deep network detection and response capabilities without affecting throughput, acting as an internal magnifying tool to monitor and detect threats. FortiDLP complements these tools by offering endpoint data loss protection with real-time alerts and monitoring, helping organizations prevent sensitive data from leaking through AI platforms like ChatGPT. These tools illustrate Fortinet’s commitment to using AI not only to protect networks but also to secure how AI itself is used within organizations.
The presentation concluded with insights into AI-Driven operational tools like FortiAI Assist, which uses generative AI for troubleshooting and management through an interactive chatbot UI. Choi highlighted that Fortinet’s architecture uses region-specific AI proxies, ensures sensitive data masking, and allows deployment flexibility between on-premises and cloud environments depending on client needs. He reinforced the message that AI security solutions need to be architected based on specific organizational requirements, not delivered as a one-size-fits-all model. Fortinet’s approach, with heavy emphasis on secure architecture and user training, positions them as a versatile partner in navigating AI’s growing footprint in enterprise environments.
Recorded live in Santa Clara, CA as part of AI Field Day 7 on October 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-ai-field-day-7/ or visit https://www.Fortinet.com or https://TechFieldDay.com/events/aifd7/ for more information.
Transcript
My name is Keith Troy. So I'm the director of product management from Fortinet. Uh, primarily taking care, uh, two areas.
One is public cloud clouds, um, or the core product goes to me. And right now I'm also stepping on AI because there's two areas Were very synergetic altogether, especially you talk about ai, the public cloud, uh, provider, hyperscaler. It's definitely play an important role.
So I can get, uh, pretty good, uh, visibility on both. So, um, yeah, lemme kick start. Uh, yeah, just a quick slice of why with we, uh, AI is important to the enterprise.
So, uh, yeah, we summarize the six reason I can further summarize into two. So one is the effect e efficiency. So you definitely need something, um, uh, to be more, um, effectively to work on the work daily to day so that you can use less resources to perform more.
And another one is, of course, driving something new. So something is not possible before, right now with ai, it's already possible. So that's why you will see more and more enterprise doing, uh, AI adoption and why it become more important to the view.
Uh, yep. I think it's, uh, max and also, um, Maggie, uh, already introduced. One is, uh, for AI in general, so three buckets right there.
ProTech, existing secure ai. So for me, from, I will use another angle, go to go deep dive on this three because from, uh, from what I, um, what, uh, message I want to bring it out is how you logically understand what is 40 ai. Because just like what, uh, yeah, you asking before is 40 AI is the kind of product of kind of portfolio.
I can tell your definition from another angle. So yep. So yes, I, I, we believe that AI problem is not that kind of, um, simple.
It's complicated. So, uh, from what perspective is we would need some architecting to solve the problem. So the most important that from customer perspective, how you, um, leverage Fortinet product to, to do that, you are more like start with, uh, at the center.
So you start with your AI requirement, or you also start with your problem on AI so that you go outward. First of all, you identify whether which category that your problems goes into it. So say for example, if you want to protect you from the risk of ai, Fort Protect is something that you want to go for it.
If you talk about, um, you have AI system to be protect, say for example, you are owning your LLM system at the back, or you are owning your machine learning model serve for your customer. So secure AI is the product category. You're going for it, of course, at the, uh, yeah, I think you already, we already cover quite a lot on so, and NOC use case, uh, to use generative AI to enhance our, uh, AI portfolio.
So basically you go thing from inside to our, and then we will met it, the use case for some of the case. That's why we are heavily mentioned that we are focused on the use case itself because, um, unlike, uh, the other vendor, we are not believing, uh, a single army knife can do all, can, will tackle all the AI problems. So we more likely we will need the capability for multiple product, and we also need architect to bring it up the solution together to have the best fit for your AI problem specifically.
Say for example, if your, uh, organization have a direction on the cost, on the, um, operation needs or even, uh, different consideration will, you may possibly leverage different kind of product in your case. So that's why I also always think that AI problem have to be architecting problem instead of one single solution problem. So, um, yeah, from what we are can help you is Fortinet would able to bring you from outside in.
So from us, we understand what the kind of product that we are offering. We will have, uh, so many, uh, architect and also, uh, uh, sales engineer to help you to bring up the solution to your use case specifically on your AI area. So we are actively experimenting, uh, even though the problem is very new on the area, we will also able to do some, um, experimenting or exploration for you together to step into the, this area.
So, uh, for the AI Protect, so you have some risk, uh, to be protect from it. So right now, um, these five feature set is a logical feature set that, um, what we think that, uh, fort I protects should have it. So it's talking about use of course.
First thing is similar to what Max is mentioning, you need to know what you're having before you can protect them once you know them, how you control the access, uh, for every single one of them who is operating on what kind of thing on where. So that kind of thing that we definitely needed. Data loss protection, I think is the most important, one of the most important areas right here.
You don't want your, uh, staff within your network leaking out their informa valuable IP information or any other things without your, um, uh, acknowledgement. So something like that. Secure wireless training, I also want to put it out right here, is definitely kind of, um, uh, use important use case to protect your organization because I think people is always be the most vulnerable component within their network.
So real time protection is also another kind of thing. So once customer, once you are user really doing something bad, immediately able to detect and mitigate is better, always better than the due to, uh, the postmortem investigation. So from now on, I will quickly give you introduction of what product available today on this area particularly.
So, uh, more likely into areas one from networking area perspective, so that you can, uh, have our product put in the network. You are already able to do it today. Another one is from endpoint perspective.
So you have may have so many, uh, staff within your network, different kind of operation system, wherever than how we protect, uh, you from endpoint as well. So for the gate, I think, uh, yeah, hopeful I'm not necessary to introduce too much on this because this is one of the, not one of the, this is the most successful product from Fortinet, um, which is, which is our next generation firewall. 4.
Also with 40 guard, uh, UTP bundle, you will be able to, uh, use FortiGate to, um, uh, protect you from Gene ai. Uh, applic, there's a new category called generative AI under application control, you will be able to create a firewall, create a detection over that. Um, uh, yeah, of course we are not just, uh, because category on gene EI is a little bit large.
So it's not only about the, uh, chapel itself, but this is also talking about other application like, um, um, meeting note taking, video editing, something like AI tools that you're using today. So all kinds of, um, detection right here. We, um, we are having, yeah, as we said, we have Tigo lab, research lab to taking care, uh, how we detect it, how to identify them in the signature basis in our research lab at the back, we are also having, um, our Tigo lab to define the risk score for every single one of them so that when you, um, uh, plug it in into a network, you will be able to see how many users are really going through, are using these kind of tools and what kinds of, um, uh, data that you can do and exactly that you would use, uh, because it's a gateway.
So we still need to maintain the throughput for altogether. So that's why, uh, you can stop the things at the edge already. Um, yeah, there's so many, um, information you can, you, you can take a look.
You can even use, uh, able to use the prompt, uh, unless they need some deep, uh, packet analysis. Um, yeah, actually I prepare a video on that. But yeah, I think that, yeah, from time being, I try to, uh, yeah, leave the video later so that you can take a look afterwards.
So, so another product I want to, uh, bring it up is called 48 NDL Cloud. So NDR means, uh, network detection response. So unlike, uh, 48, 48 is putting at edge the gateway.
So it's, uh, more like inline inspection, but anti iCloud is more like, um, uh, something like I ideas something like this, uh, that kind of product it will put within your network, because the most important that it won't affect your network throughput because it's not on the gateway side, but live it in your network so that, uh, we will, uh, install so many, uh, sensor into your network so that you can replicate your packet, uh, to the NDL cloud solution so that we can do some, um, threat, uh, hunting and deep analysis. So, uh, we, uh, yeah, the PM always told me that 40 N-D-N-D-R or NDL cloud is like a magnifying glass of 40 K. So FortiGate would, uh, capture, um, uh, some of the, the usage, but if you need some deep analysis on how the usage pattern, you definitely would, uh, go for NDR instead.
So, but, but basically we need both. Uh, yeah, the, right now I think it's already, uh, it's already in ga, so we got JR usage observation on net L cloud already. So, uh, if you're using our surface, you are already able to, uh, see the Gene R usage on your network.
Um, nowadays on the top, you can create a detector, of course, you can observe it, you can detect it, and you can also, um, through the, um, detection and observation dashboard, uh, from host's perspective, you are, you are also able to, um, draw this, um, sequence of event, um, so that you can, uh, perform the flat hunting altogether. Yeah, of course, we capture every single network metadata, uh, throughout the process. So in, in, in order, you need to deep, uh, some carry some further investigation.
You will also having all the information capture for you as well. Yeah, on the top, there's so many things top by NDL, not even talk, I'm not even talk, start talking about how they use our machine learning, uh, to do the enormous detection or, uh, categorization in the long run, because they, they, yeah, this is already some very, um, features already, but Jenny EI particularly is, uh, superior. You, Sorry, press something wrong Here.
Oh, yeah, I'm back. Um, yeah, there dashboard as well. So I also have another video, but I better skip, uh, in less than 10 minutes.
So, um, DOP is another, uh, yeah, just mention a little bit. 40 DP is our data loss protection solution. So it is an endpoint solution.
So that means, uh, yeah, it is a multi os support. Multi OS is also, um, you have instance responsibility what your customer, what your user is doing on your computer. So, um, yeah, you, you will, uh, later on, they will integrate into an agent code the endpoint all together so that they can collect the data from endpoint and then they can take action from endpoint perspective already.
So it's more like a real time, um, uh, data loss protection solution. So, uh, yeah, I also having, um, uh, videos right here, but yeah, let's see if I can play with it. I think this one will have to, to play a little bit.
It, it would be, you know, I think one of the, the questions from earlier Yep. Be great if, uh, to highlight a little bit about how ai, our AI and DLP, um, materializes some of the end results that, that we're talking about. Yeah, so say for example, if a customer, if your end user on your computer, on the computer using chat GPT, the 40 endpoint will be able to detect and stop them.
And also, um, having the warning right here, because some, somebody will also need to do some real time education when customer using this, uh, kind of gen AI tool. Um, yeah, of course, when the customer really pays some code, just like, just like hit here, go to she GBT, ask for explanation, that means they are already leaking some API keys right here. Um, you will be able to see that, uh, the solution, uh, would be already be, um, detected the kind of thing.
So everything will be captured, detected, and also response as well. And the most important as, um, uh, security analyst, what you are going to do is you also have a centralized dashboard to show what kind of user using what kind of tool and what violation they're doing so that you can take action right away or immediately in order to mitigate a risk. So, so that's alerting, that's monitoring and alerting Monitoring, right?
Stop any actions. Correct. It will stop action, uh, very soon.
It's a roadmap item. Okay. Yeah, of course.
But you have, you still have the notify hockey analyst. Yeah. Hey, she's Scott's Bad thing.
Exactly. Forward the, forward the message to HR or something like that. So yeah, Scott done view with his open ai, right?
Yeah, yeah. Trying to put that in gi what else would you put it? Lovable, of course.
Yeah. So of course. Um, I would say, yeah, I also mentioned that human is the most vulnerable component in the organization, for sure.
Are the weakest One. Yeah, we are the best. But yeah, I, I think that is our, yeah, that's always true.
So the training, we all also is a part of our, uh, port portfolio to make sure that our users being well educated before they really using AI and know what is the risk coming from ai. So, uh, yeah, the course is already in GA already. So next, um, for the AI assist, so I think I was talking a little bit more before how, how they use, um, law and soc.
Um, yeah, just similar slide and if you're interested, yeah, I think I, I got, just got six minutes. I have to, uh, skip this video, but this video talking about what exactly our product for the analyzer and for the manager we are doing, uh, to provide some interactive troubleshooting. So, uh, what they're doing is more like you ask the system what's going on and the system will, uh, check it for you and recommend the next action, and you are also able to verify the action accordingly in the 40 analyzer.
Um, it's more like, it, it's, I always say this word we have in CLI before we have, we for our all kinds of interactions. So I also say that check bot is our third UI to, for you to interact, because as a human, I'm not necessary to use CI all times of myself. I sometimes may use gui, but the most important thing right now, I can use a check bot to go over my checking as a human curated, um, network, um, uh, process.
I also need to take action. So that's why, um, 40 I, right 40 I assist right now would still pass the action to you so that you are the one who, who could click the button. But with the, um, GM model right now to help, this is greatly help you to, um, uh, use a way lot more less time on the investigation itself.
So all kinds of data, um, uh, how to mining the data, how to, uh, summarize the thing totally you can be done on Gene. So from data perspective, whatever question that I can answer, maybe in breakout session a little bit more if you, you're interested, but yeah, there's almost like likely the features Is the chat assistant, um, um, accessible through the API or programmatically, or is it just through the interface, uh, Fluid through the interface at this moment? But if you are talking about flu and other kind of, uh, interface, not within the product, uh, yeah, maybe I can, I can discuss a little bit about with you Yeah.
Afterwards. So for manager, have a very similar use case as well, but how you use, uh, yeah, this one is the most interesting one. You use image to create the SD overlay by, right, by drawing the, the, um, the diagram that you want and then upload it to, to the model, and then they will generate all kinds of SDN overlay command line for you.
You just one click and then the SD wan, um, we've already deployed it and you can also verify within the Google as well. So, um, but this one, yeah, I think this one is, is, is very interesting. So yeah, you can upload this kind of thing.
Yeah, and they will generate for you and then one click deployed it, and then you can verify it as well. So, um, yeah, just a little bit long. So 40 manager, oh yeah, of course.
Similar troubleshooting is sort other, uh, things that, um, 40 manager always be doing. So say example, we FD wan, SD-WAN does a repent tunnel is down the, the 40 I assist will able to detect it, suggest a solution, and you can also take action to mitigate it, uh, through the, um, um, the model. The model will be able to suggest what is next step accordingly.
So yeah, so We also inject the natural language, so you don't need to type Yes, you can speak to it, right? Yeah. So I would demystify a little bit about what 40 I is behind the scenes.
So I think some questions around this one as well, uh, as a user, uh, they will always, they always interact with the product by here, uh, manager Analyzer asking the question through the channel interface. But behind the scenes, actually, it's the, uh, SaaS, um, hosted by Fortinet Act. We have a two major component for sure.
One is the AI proxy. So the proxy is, um, a proxy service hosting in Fortinet data center. Uh, right now, I guess there's two in US and two in emea.
So we are building, uh, the same thing for, uh, APAC as well, so that all kinds of, um, product you are interacting, they will send, they will have a message with their proxy behind the scene. Of course, I will say that we always use the right model for the right problem. So every, there's so many, uh, products supporting for data assist, you may, there may not be one single model or language model can support, uh, all the things perfectly, or not necessarily too big to serve all the product.
So, uh, each single product is even down to every single feature. We can leverage different kind of backend. Say for example, you can.
Um, yeah, we are exploring, uh, using, um, the model on different cloud provider. We are also able to host our own, uh, GPU on our data center to, uh, do the, uh, influencing on the A LM as well. Um, we also can run some customized, um, uh, fine tune the, uh, language model as well.
Really can be down to use case per use case. So at the end of the day, your data, um, will be handled by all the fortine, um, um, infrastructure, including even in the cloud is maintained by our cloud account as well. So how we secure the security parameter is totally done, the Fortinet.
Um, but the one, so, So on on-prem or cloud, like you, you, you can deploy this wherever is optimal for the customer's application infrastructure, is that what you're saying? Um, sorry, product. Yeah, yeah, yeah.
So for the proxy mm-hmm. Um, The proxy is globally, uh, available a around globally. So each region we will have, uh, some pop over there.
So your product will interact if you're using the, the, the, the interface, it will interact with your closest geographical location proxy server for the operation. But that proxy is hosted by, is maintained by Fortinet. You, you can't deploy it on deploy it.
OnPrem, it's Good question. You are asking about our software and ai, Uh, I'm thinking about latency in the application. Yeah.
Um, yeah, well, we are both, we are, uh, right now we are also doing some research on, on both because if we, if we can run it on, uh, the cloud backend, we can, why not? We are, we are able to run and data center. Uh, the point is really depends, as I said, it really depends on use case because for, say example, if I led you to run it on your data center, the size of model, how we do the model maintenance and how is the wrap pattern being in, in, um, introduced, there is some more technical details that we need to concern it when we these decipher it.
But software AI is definitely something that, um, we are always looking into it. So some of the product may be able to already, uh, go in software, um, depends on whether the form factor they're offering. So that's a fair answer.
Thanks. Yeah. Uh, yeah, uh, yeah.
The one important message I want to put out for last slide is the sensitive data would not like leave the product by itself. Say for example, you're using analyzer manager when you, um, key in something sensitive, including what, uh, ip, IP address may address end pointing, all kind of thing would be totally masked before we send it out even, uh, to our fortine infrastructure. Uh, and that is the case that, uh, our 45 AI proxy will also keep, will keep some, uh, will keep your, uh, conversational chat for 90 days for support only.
But that means even though from Fortinet staff, we are even unable to retrieve what you are actually sending. So not even talking about the backend at the end, uh, host by public cloud provider, or even host by Fortinet. We don't know.
We don't know the message exactly, but at the end of the day, we translate back in front of the user size. So yeah, the sensitive data definitely won't leave your product when you use this thing. Do you have any significant user validation that they're okay with this?
Oh, yeah. Um, that means if sometimes when, uh, when we having, uh, this kind of, uh, um, solution, I receive quite so many kind of, uh, RFP on asking what is the infrastructure in between. Sure.
So by making sure which product they're using, and we will make sure that all the 40 ai assist enabled product, uh, follow exactly the same pattern so that we will have a unified, um, uh, risk assessment so that we can provide the user. Okay. Yeah.
RE is also another, um, yeah, truth grounding is so many way for doing that, right? So re is the one of most, um, commonly used pattern. We were putting our vector store and AI proxy together.
When question comes through it, uh, you will search the documentation with, um, um, the closest, uh, data before we go to the forensic. So, um, OPT option, yeah, uh, opt our feature is also important. One's small, but it's more important customer according to the policy, they would be allowed to opt in an by themself when necessary.
Uh, okay. Just, just very quick. So for secure ai, uh, yeah.
Or you, Is it opt-in by default? Sorry? Is it Opt-in by Default?
Should be default or about default or about default? You need post, yeah, the most important need customer to turn it on before use it. Yeah, good question.
Secure ai. So how, if your, um, system, AI system want to protect this is portfolio, you want to look into it? Uh, yeah, some facts, some, some facts are more than 70%, uh, enterprise using right now, but not necessarily everyone making profits.
So only 5% is working, but we're still looking for it. Here is the logical features set that, um, we are building around it, including s uh, uh, ISS form and also even motor cloud, rail lane protection agent AI protection as well. But yeah, please allow me, uh, yeah, today is, um, yeah, it's more way closely to the Q4.
There's so many new announcement really comes from a new product, so they will have some of them we've already, already been covered or some of them already been development, so I cannot, yeah, I'm not, um, uh, yeah, talk up too much. But yeah, please stay tuned for all the 49 announcement, especially a couple days later. Um, or swap top 10.
Definitely. This diagram is not new to everyone. Uh, when you create a uh, LM system, this is everything that you need to cons all the components basically is right here, A MLM, uh, swap, top 10, each one of them.
What kind of director is going to here? Uh, we will have a product to deal with this very soon. Uh, yep.
Last Bais cloud field. Uh, we also for also having cloud field day 24, a couple days ago, they also sharing, uh, what kind of, um, example, uh, sample application, how to use our fort product, uh, to protect their, um, agent workload behind the scenes. So yeah, it's more like, um, uh, yeah, please just also, uh, go the watch how we practically let the architect to solve your problem, uh, with our pro, uh, tool set.
So Fort ai, as, as I mentioned, again, this is a product portfolio which help you to cater all kinds of AI problem. Uh, so you, we need to, um, in case you're having even very new problems, just come to us. So, yeah, so I, so, uh, just two quick call to action.
So once you have AI requirement or problem, try ask them, make sure that which, uh, category, uh, is falling into it, I guess. And then contact Fortine to, uh, to learn more. So we will help somebody help you.
Last but not least, educate your people, um, with all the AI risk and, uh, this corresponding security. So yeah.