FortiGuard AI-Powered Security Services
This solution brief shows how FortiGuard AI-Powered Security Services deliver always-on, multilayered defense against sophisticated traditional and AI-driven threats, backed by FortiGuard Labs intelligence. The services integrate with the Fortinet Security Fabric and offer flexible purchasing options, including bundles and enterprise agreements.
What are FortiGuard AI-Powered Security Services?
FortiGuard AI-Powered Security Services are a suite of cloud-delivered security services that help you protect your entire attack surface—on-premises, in the cloud, and across hybrid IT/OT environments.
They use AI and machine learning to continuously identify, detect, and respond to both traditional and AI-driven threats in real time. This includes:
- Ransomware, malware, viruses, spyware, and phishing
- Zero-day exploits and never-before-seen threats
- DNS-based attacks, C2 communications, and botnets
- Emerging AI-powered risks such as promptware, data poisoning, shadow AI, data loss and exfiltration, and polymorphic malware
The services are tightly integrated into the Fortinet Security Fabric and FortiOS, so protection is applied consistently across:
- Networks and hybrid mesh firewalls
- Web, DNS, and email traffic
- Cloud workloads and SaaS applications
- Endpoints, IoT, and OT/ICS environments
Behind the scenes, FortiGuard Labs processes trillions of events from millions of global sensors, enriches that telemetry with expert research and hundreds of threat intelligence partners, and feeds back real-time, AI-powered threat intelligence into the services. This helps you maintain a strong, always-on security posture across a distributed and constantly changing attack surface.
How does FortiGuard use AI to improve threat detection and response?
FortiGuard AI-Powered Security Services use AI and machine learning at multiple layers to improve both speed and accuracy of protection.
Key ways AI is applied include:
- Real-time threat intelligence: FortiGuard Labs uses AI/ML to analyze trillions of security events from millions of Fortinet sensors worldwide. This produces continuously updated, actionable intelligence that is automatically shared across the Fortinet Security Fabric.
- Inline malware prevention: AI-based inline malware prevention holds suspicious files in a queue and makes a verdict in real time, using advanced ML models and hardware acceleration in FortiOS. This helps block previously unknown threats before they execute.
- Behavioral and correlation analytics: Services like URL and video filtering, DNS filtering, IPS, and anti-botnet use AI-driven behavioral analysis and threat correlation to spot malicious URLs, domains, and network patterns with minimal false positives.
- Static and dynamic malware analysis: AI-powered analysis supports detection of ransomware, crypto-malware, and zero-day threats, mapped to MITRE ATT&CK for better investigation and reporting.
Because these capabilities are integrated across NGFW, SD-WAN, email, endpoint, OT security, and more, you get:
- Automatic, real-time protection instead of manual signature updates
- Faster detection and response to outbreaks and indicators of compromise
- Proactive defense that adapts as attackers adopt new AI techniques
The result is a more proactive, layered defense that helps your security team operate faster and with better context, while reducing time spent on manual research and reactive incident handling.
Which specific FortiGuard services can I use, and how are they packaged?
FortiGuard AI-Powered Security Services cover a broad set of use cases, and you can adopt them individually or as bundles depending on your needs.
Key service areas include:
- Web and DNS security
- URL and video filtering: AI-driven, cloud-delivered web filtering that blocks ransomware, credential theft, phishing, and other web-based attacks, with granular category controls and logging.
- DNS filtering: Protection against DNS tunneling, protocol abuse, infiltration, C2 domains, and domain generation algorithms, with visibility into DNS traffic and blocking of high-risk domains (e.g., newly registered or parked domains).
- Network and endpoint protection
- Intrusion prevention system (IPS): Thousands of signatures, including models trained on Cobalt Strike data, to detect and block advanced network intrusions and evasion techniques.
- Antivirus: Real-time updates to stop polymorphic attacks, ransomware, viruses, spyware, and other content-based malware across network, endpoints, and cloud.
- AI-based inline malware prevention: Real-time blocking of previously unknown threats using AI/ML and FortiSandbox integration.
- Data, cloud, and SaaS security
- Data loss prevention (DLP): A consistent DLP pattern database integrated across Fortinet solutions to enforce policies and prevent sensitive data loss or breaches.
- Inline and API CASB: Visibility and granular control over SaaS apps, integrated with FortiGate NGFWs, SASE, and FortiClient for ZTNA inspection and posture checks.
- OT, IoT, and attack surface management
- OT Security: Deep visibility and control for 100+ ICS/SCADA protocols and industrial devices, with OT-specific vulnerability and application signatures, device/OS detection, and IoT hardware mapping.
- Attack Surface Security: Continuous assessment and rating of your security infrastructure, automated discovery, segmentation, and vulnerability correlation for IoT devices.
- Threat detection, email, and C2 control
- IOC and outbreak detection: Automated breach defense that monitors for ongoing attacks, vulnerabilities, and persistent threats, with detailed outbreak alerts for SOC teams.
- AntiSpam: Works with FortiMail to reduce spam and email-borne infections more effectively than basic blocklists.
- Anti-botnet and C2: Dynamically blocks unauthorized communication with compromised remote servers and malicious sources tied to web attacks, phishing, scanning, and scraping.
Purchasing and packaging options:
- A la carte: Select individual services to address specific gaps.
- Bundles optimized for use cases:
- Enterprise bundle: Broadest coverage, designed for comprehensive security at a lower cost per service.
- UTP bundle: Focused on enhanced web security.
- ATP bundle: Designed as a first line of defense for network and file security.
- Enterprise Agreement: Flexible commercial model for organizations standardizing on FortiGuard AI-Powered Services.
This mix-and-match approach lets you reimagine your security stack at your own pace—starting with priority areas like web, email, or OT, and expanding to a more unified, layered defense across the Fortinet Security Fabric.

