Saturday, October 10, 2026

Fortinet warns of cyber risks from shadow AI, fragmented security tools

Cybersecurity firm Fortinet is pushing an AI-native approach to enterprise security as organizations face growing threats from artificial intelligence (AI), unauthorized use of generative AI applications, and increasingly fragmented security infrastructure.

At the Fortinet AI Cybersecurity Summit 2026 in the Philippines, company executives warned that the proliferation of security tools and AI-powered cyberattacks is making it more difficult for enterprises to detect and respond to threats.

According to Fortinet, a typical organization may use around 43 cybersecurity tools, many of which operate independently, creating visibility gaps and overwhelming security teams with alerts.

The challenge is compounded by the need to protect legacy systems, cloud infrastructure, mobile devices, bring-your-own-device environments, and Internet of Things (IoT) deployments while dealing with limited budgets and regulatory requirements.

The rapid adoption of generative AI has also introduced new security risks, particularly as employees increasingly use unauthorized AI applications for work-related tasks.

The practice, known as shadow AI, can expose organizations to data leakage when employees upload confidential information, personal data, or trade secrets to public AI services without adequate safeguards.

At the same time, cybercriminals are using AI to automate and scale attacks, from reconnaissance and exploitation to the creation of deepfake audio and video and highly personalized phishing campaigns targeting user credentials.

To address these threats, Fortinet is promoting its AI-native Security Fabric, which integrates AI capabilities across networking, security operations, and threat intelligence rather than relying on separate AI tools.

The platform is designed to allow different security products to exchange threat intelligence and contextual information, enabling coordinated responses across an organization’s infrastructure.

One of its key functions is AI governance, with Fortinet claiming its platform can identify more than 6,500 AI applications.

This allows security administrators to monitor which AI services employees are accessing, distinguish authorized applications from unsanctioned ones, and enforce policies governing the information that can be shared with these services.

Fortinet is also extending its security capabilities to enterprises developing their own large language models (LLMs) and AI applications.

These controls are intended to protect AI training data, prevent unauthorized extraction of information from AI models, and mitigate threats such as data poisoning, in which attackers manipulate training datasets to compromise model behavior.

For organizations running their own AI infrastructure, Fortinet highlighted its integration with NVIDIA hardware, which is intended to provide security protection without significantly affecting AI processing performance.

The company is also incorporating agentic AI into security operations to automate investigations, correlate threat intelligence, and provide analysts with additional context when responding to incidents.

Fortinet said the approach could help reduce false positives and false negatives, shorten threat detection and response times, and ease the workload of security operations center (SOC) personnel.

The company also claimed that sharing intelligence and using a common AI model across security functions could lower token consumption and operating costs associated with AI-powered security operations.

However, the effectiveness of such an approach depends on how well organizations integrate their existing security infrastructure and establish policies governing AI usage.

Bambi Escalante, country manager of Fortinet Philippines, said the growing use of AI requires enterprises to reassess their cybersecurity strategies.

“AI has changed how attacks are being done, how organizations need to respond, and what organizations need to protect,” Escalante said.

She emphasized the need for organizations to balance AI adoption with cyber resilience, including their ability to anticipate, withstand, recover from, and adapt to emerging threats.

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img