Fortinet applies AI within security and network operations, where an assistant can help analysts interpret telemetry, investigate detections and prepare changes. FortiAI also covers governance of AI use. It is a portfolio of capabilities embedded in different products, so the practical buying decision starts with the deployed product and version. A general FortiAI announcement does not establish the same features, license or action permissions everywhere.
- 01The offer AI assistance and AI security controls across Fortinet’s Security Fabric.
- 02The fit Security and network teams whose investigation work already depends on Fortinet telemetry and administration tools.
- 03The boundary This public-source assessment proposes a read-only investigation pilot; it does not claim tested detection quality or autonomous remediation.
01 / ProductIdentify which Fortinet product is doing the work
The FortiAI-Assist page describes AI-supported investigation, configuration and orchestration across products including FortiAnalyzer, FortiManager and security operations tools. The important distinction is the host product. An assistant operating on network management context performs a different job from one examining a security detection, even when both use the FortiAI name.
The AI governance page addresses discovering and controlling AI use, including unsanctioned applications and data movement. That is a separate responsibility from helping an analyst investigate a threat. An organization may need both, but should not assume that enabling an assistant also establishes policy over every employee’s use of AI.
The FortiNDR Cloud 26.2.a guide documents conversational investigation and detection triage. It provides a concrete starting point for evaluating how AI interacts with existing network evidence. The platform’s generated interpretation still needs to be assessed against the actual telemetry and the organization’s incident response process.
02 / AudienceChoose the analyst task before comparing AI features
Fortinet is relevant when analysts repeatedly reconstruct network activity or administrators spend time interpreting product-specific configuration. The assistant’s useful context comes from the system in which it operates. That can reduce the work of moving between interfaces, but it also means the quality of the underlying telemetry and deployment coverage remains central.
An operations team with inconsistent asset ownership may receive a fluent description of activity without knowing who should act. Before a pilot, identify who owns the affected systems and who can authorize containment. An AI explanation should make the handoff clearer. It should not turn the analyst who asked a question into the implied owner of every recommended action.
The CrowdStrike blueprint is relevant when endpoint investigation is the main operational starting point. The Palo Alto Networks blueprint offers a comparison for broader security operations and AI protection. Compare the evidence each system can see and the actions it can support, using the same incident definition.
03 / WorkflowA proposed read-only investigation of unusual outbound traffic
Consider a security team examining an unusual outbound connection from a managed workstation. This proposed pilot uses FortiNDR Cloud to help assemble an investigation summary. It does not automatically isolate the workstation or change a firewall rule. Start with a known historical incident and benign examples that resemble it, so the evaluation tests discrimination as well as narrative quality.
Establish the original evidence first: affected entity, observation window, destination and the detection that triggered review. Preserve timestamps and the underlying record identifiers. A generated statement that activity is unusual has limited value if the analyst cannot determine which baseline or observation period supports it.
Ask the assistant to summarize the detected behavior and identify the evidence relevant to each suggested explanation. The pilot should distinguish an observed connection from an inferred intent. Software updates, synchronization and malicious activity may share superficial traffic patterns. The summary needs to make the difference between evidence and hypothesis visible to the analyst.
Expand the time window deliberately. A short view may miss a recurring legitimate task; a long view may combine unrelated activity from different users or device states. Have the analyst record why a particular window was chosen. That turns a conversational investigation into a reproducible case rather than a sequence of prompts that no one can later interpret.
Check asset ownership and recent approved changes through the existing operational process. If an assistant cannot see that information, treat it as an explicit evidence gap. Do not ask the model to infer authorization from technical activity alone. A connection can be technically expected yet unauthorized, or authorized but misconfigured.
Prepare a proposed next step that names the affected asset, reason and required approval. The security team might request additional evidence, contact the system owner or invoke an existing containment procedure. Keep those actions outside the initial read-only pilot. This lets the team assess investigative usefulness before introducing additional consequences into the test.
Review benign cases with equal care. A useful assistant should help analysts explain why an alert does not require escalation, while retaining the evidence used to reach that conclusion. Measure unsupported assertions, omitted context and time spent checking the generated account. Faster text production alone is not a meaningful improvement in investigation.
Finally, preserve the manual investigation route. If the assistant is unavailable or its usage allowance is exhausted, the team still needs to inspect detections and perform its established response process. The pilot should show that AI assistance improves an operating system whose essential functions remain understandable to the people responsible for it.
04 / PricingLicensing follows the product and version
| Product / release | Documented basis | Important boundary |
|---|---|---|
| FortiNDR Cloud 26.2.a | Valid FortiAI license; token subscription | Monthly allowance and product-specific evaluation terms |
| FortiManager 7.6.5 | Valid FortiAI license | Up to three local administrators |
| FortiADC 8.0.2 | Supported platform license and support requirements | Beta; platform-based monthly tokens |
| Broader FortiAI portfolio | Product-specific commercial scope | Do not transfer one product’s entitlement to another |
Version-specific terms from FortiNDR Cloud 26.2.a, FortiManager 7.6.5 and FortiADC 8.0.2, consulted 23 September 2026. No monetary list prices established.
The commercial evidence is product-specific rather than one public FortiAI price list. In FortiNDR Cloud 26.2.a, the guide describes a one-year token subscription with monthly allocations, no rollover and temporary suspension when the allowance is exhausted. Starter tokens are a one-time FortiNDR evaluation allocation. Monetary prices were not established in the consulted documentation.
FortiManager 7.6.5 administrator guidance states that FortiAI access is limited to three local administrators and requires a valid license. That is consequential for shift coverage and centralized identity arrangements. It should not be generalized to every other product simply because the assistant shares a name.
FortiADC 8.0.2 documentation describes a different arrangement: the assistant is Beta, supported licensed platforms receive monthly allocations, and VM access requires active FortiCare Premium or Elite support. The page says token top-ups are not supported for that release. These differences make a product-by-product entitlement review essential.
05 / DistinctionsEmbedded context is valuable when its limits remain visible
FortiAI’s position inside operational products can be useful because the analyst begins with an existing detection, log or configuration context. The assistant does not need to become a separate destination for every security question. That reduces one kind of handoff, provided the generated explanation retains links to the evidence that staff normally use.
The portfolio also distinguishes assistance from governing AI activity. A security team can ask two different questions: how AI helps its own investigation, and how it manages AI use elsewhere in the organization. Keeping those questions separate helps assign the correct owner and avoids purchasing a broad capability that does not address the immediate operational problem.
The AI governance material includes strong claims about accuracy and false positives. Those statements are vendor positioning, not results established here. For a real evaluation, use the organization’s own detection mix and record both useful findings and unnecessary escalations. A test restricted to selected malicious examples cannot establish the day-to-day burden on analysts.
06 / QuestionsConfirm data handling and the authority to act
What information is sent to the inference service for the selected product and version? FortiNDR documentation discusses masking, but its general feature text and detailed privacy wording differ in their description of address coverage. Do not infer universal masking of every sensitive field. Request a precise data-flow explanation and test with approved synthetic identifiers before expanding use.
Which users may use the assistant, and which permissions do proposed actions inherit? The FortiManager local-administrator restriction is one example of a rule that can affect an otherwise attractive rollout. Confirm the actual identity and authorization model instead of assuming that a conversational interface uses the same boundaries as every other administrative function.
How does the team handle generated configuration or remediation? An explanation, proposed command and executed change are distinct states. Require a reviewable change with a rollback plan before enabling actions in a live environment. The initial investigation pilot can establish whether suggestions are useful without treating the assistant’s ability to produce a command as permission to run it.
07 / DecisionEvaluate the assistant within an existing response process
Fortinet is worth assessing when AI assistance can use the telemetry and product knowledge already central to security operations. Choose a narrow investigation task, a specific supported release and a named analyst group. Confirm entitlements before the pilot, then judge the assistant by the quality and traceability of its contribution to actual cases.
For unusual outbound traffic, the desired result is a concise, evidence-linked account that helps the analyst choose the next authorized step. Once that works, examine whether additional automation improves the process. Keep investigation quality, execution authority and AI usage governance as separate decisions with their own evidence.
Improve network investigation
Pilot read-only summaries against historical malicious and benign cases.
Generate operational changes
Require reviewed diffs, explicit approval and rollback before enabling execution.
Govern employee AI use
Evaluate the relevant AI discovery and policy controls as a distinct deployment.
A business worth understanding.
Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.
Suggestions are free. Selection and publication stay with the desk.
- FortiAI-AssistConsulted
- Fortinet AI governanceConsulted
- FortiNDR Cloud 26.2.a FortiAI guideConsulted
- FortiManager 7.6.5 administrator accessConsulted
- FortiADC 8.0.2 FortiAI AssistantConsulted


