Fortinet Accelerate 2026: What I Took Away From Three Days in Las Vegas

I spent three days at Fortinet Accelerate 2026 in Las Vegas and came away with a lot to think about. This is my honest take on what stood out technically, what genuinely impressed me, and where I think the questions still need answering.

First Impressions: This Was Not a “Features” Conference

I have been to enough vendor conferences to know when a company is showing you a feature list dressed up as a strategy. Accelerate 2026 was not that. From the opening keynote through to the technical breakouts, the message was consistent and  I think  genuinely important: AI has changed the threat landscape in a way that makes speed the only meaningful defence metric.

Ken Xie said it plainly on day one: “Security operations need to function at the same speed and with the same coordination as the attackers”. I work with organisations that are still largely manual in their workflows, and the gap between what attackers can now do with AI-assisted tooling and what defenders can respond with is widening fast. Accelerate felt like Fortinet had genuinely internalised that problem and built a roadmap around solving it  rather than just talking about it.

The dual AI theme ran through everything: AI as the thing you need to defend against, and AI as the mechanism you use to defend. It is not a new narrative, but at Accelerate 2026 the specific product announcements gave it much more substance than I have seen before.

 

FortiOS 8.0: The Announcement That Mattered Most to Me

I did not expect FortiOS 8.0 to be the thing I kept coming back to. But it was. This release marks 25 years of Fortinet’s OS evolution, and for the first time I feel like the AI security story in the platform is operationally real rather than aspirational.

AI-Aware Application Inspection: The Feature I Wish We Had Had Two Years Ago

Every organisation I speak to has the same problem right now: employees are using generative AI tools  ChatGPT, Copilot, Claude, specialist coding assistants, and a dozen other things  and nobody has a proper governance picture of what data is going where. Shadow AI is the new Shadow IT, and it is arguably more dangerous because the surface area is your entire user base and the risk is data exfiltration at scale.

What impressed me about the AI-aware application control in FortiOS 8.0 is that it does not try to solve this with a blunt ‘block ChatGPT’ policy. It gives you action-level control within AI applications. You can permit a specific team to use an approved GenAI tool while blocking the ability to paste large documents, upload source code, or submit content that might include customer PII or regulated data. That is actually useful. That is the conversation I need to be having with security teams, not ‘should we block it or not.’

The technical capabilities that make this work:

  • FortiView for AI attack surface a new visibility pane that maps sanctioned versus unsanctioned AI tool usage across your estate. Finally a way to actually see the Shadow AI problem rather than just know it exists.
  • AI-aware application control action-level policy enforcement rather than app-level allow/deny. This is the meaningful distinction.
  • MCP and agent-to-agent (A2A) visibility as agentic AI architectures start appearing in enterprise environments, this reveals hidden interactions between apps, AI agents, and tools. The blind spots where data silently moves between systems are exactly where I would expect problems to emerge.
  • Enhanced DLP with OCR the DLP engine now reads sensitive data embedded in images, screenshots, and scanned documents. This closes an exfiltration bypass that has been sitting there for years. I have seen this used in pen tests. It is good to see it addressed.

 

Quantum-Safe: I Am Not Panicking Yet, But I Am Glad They Are Thinking About It

Post-quantum cryptography is not keeping most security teams up at night today, but the ‘harvest now, decrypt later’ reality means the clock is already ticking on long-lived sensitive data. FortiOS 8.0 extends PQC into management and SSL inspection paths  using algorithms like ML-DSA and hybrid key exchange that maintains encrypted inspection without silently downgrading connections. Quantum-resilient VPN and agentless ZTNA are also in scope. I appreciate that Fortinet is building this in now, before the pressure arrives, rather than scrambling to retrofit it.

Sovereign SASE: A Genuine Win for Regulated Sectors

SASE Outpost  enabling on-premises or private data centre security enforcement with centralised cloud policy management  is something I know specific customers will be immediately interested in. Certain regulated industries and public sector organisations simply cannot have certain data traversing public cloud infrastructure. The sovereign SASE option directly addresses that constraint. It is not the flashiest announcement at the conference, but it unblocks SASE adoption for a segment of the market that has been stuck.

 

FortiAIGate: The Product I Did Not Know I Needed to Talk About

I went into the FortiAIGate sessions with mild scepticism. Securing LLMs felt like a niche concern  something for organisations running cutting-edge AI research, not the mainstream enterprise customers I typically work with. I came out of those sessions with a completely different view.

The reality is that private LLM deployments are scaling faster than most security teams have recognised. Organisations are integrating models into customer-facing applications, internal knowledge bases, development tooling, and operational workflows. And as they do, they are introducing a security surface that conventional firewalls, WAFs, and DLP tools were never designed to address  because those tools understand packets and URLs, not natural language interactions.

FortiAIGate sits between your applications and your models as a runtime security gateway. It monitors every request and response in real time and applies AI-specific guardrails in the data path. The threat coverage that resonated most with me:

  • Prompt injection and jailbreaking crafted inputs designed to manipulate LLM behaviour or bypass guardrails. This is already a well-documented attack class and it will only grow as LLM deployments proliferate.
  • Data leakage from AI outputs LLMs that have been trained on or have access to sensitive data can inadvertently expose it in generated responses. FortiAIGate scans outputs and blocks PII exfiltration before it leaves.
  • Model poisoning and adversarial manipulation protecting against attempts to alter or degrade model behaviour through crafted inputs.
  • Compute abuse and DDoS against AI infrastructure this one is underappreciated. GPU-backed AI workloads are expensive. Rate limiting and abuse controls tuned specifically for AI inference paths protect both availability and budget.
  • Cost governance monitoring and limiting resource-intensive queries. I have spoken to organisations that had significant unplanned compute bills from runaway or malicious query patterns. This matters.

The architecture is GPU and SmartNIC-accelerated for low-latency proxy offloading  which matters because adding an inspection layer to AI inference paths needs to be fast or it becomes a bottleneck. And it integrates directly with the Fortinet Security Fabric, feeding AI-specific threat telemetry into FortiGate, FortiSIEM, and FortiAnalyzer. That means AI infrastructure events surface alongside your conventional network and endpoint events  the same operational picture, not a new silo.

My honest take: FortiAIGate is addressing a real and growing problem, and being early matters here. The organisations that build AI security governance now will be in a significantly better position than those scrambling to retrofit it after an incident.

 

The Security Fabric as an AI Platform: This Is Where It Gets Interesting

Something shifted in how Fortinet talks about FortiAI at this conference. In previous years it felt like a roadmap feature  promising, but not yet something you could really operationalise. At Accelerate 2026, the conversation moved to agentic AI: autonomous workflows that actually execute security tasks, not just suggest them.

What this looks like in practice for a SOC is FortiAI agents handling alert triage  working through thousands of events in seconds, prioritising by actual risk rather than rule-hit count, and executing predefined containment playbooks without waiting for an analyst to pick up the ticket. For a team that is currently drowning in alerts, that is not a marginal improvement. That is a different way of operating.

I also found the multimodal input support for FortiAI Assistant genuinely useful for network operations teams  not just text queries, but voice and even the ability to upload network topology diagrams and get configuration recommendations. That reduces the cognitive load on engineers who are managing increasingly complex environments and who do not always have time to construct precise CLI queries. Natural language is a legitimate interface for operations tooling at this point.

FortiSOC: The Preview That Got My Attention

Fortinet previewed FortiSOC at the conference  a cloud-delivered offering that consolidates FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiTIP into a single integrated service with a unified data model. I want to be careful not to get too excited about a preview, but the architecture is compelling. The key problem it solves is the context-switching that currently forces SOC analysts to jump between four different tools to correlate a single incident. A unified data model that normalises telemetry from both Fortinet and third-party environments, with a single console for log ingestion, correlation, automation, and case management, is what most SOCs actually need.

It is still a preview and I will reserve final judgement until it ships and real customers have run it at scale. But the direction is right.

 

FortiCNAPP: The Cloud Security Story Has Grown Up

I have been in a lot of cloud security conversations over the past few years where the discussion centres on runtime detection  catching misconfigurations after they are deployed, alerting on the exposure, and hoping someone acts on it. The problem with that model is that by the time you detect the risk at runtime, it has already existed in production for however long your deployment cycle took.

What struck me about the FortiCNAPP sessions was that the conversation has moved on. Risk originates much earlier  in code, in CI/CD pipelines, in IaC templates, in how identities and permissions are configured before anything is ever deployed. FortiCNAPP’s lifecycle-centric approach addresses that full picture. It spans from repository scanning and pipeline security through to runtime protection and data classification, giving a unified risk context across code, infrastructure, identities, data, and running workloads.

The Three Use Cases That Resonated

  • Risk-based cloud security operations: Moving from managing alert volume to focusing on exploitability. The ability to show a security team ‘these are the five issues that represent a real, exploitable attack path to your most sensitive data’ versus ‘here are 3,000 findings’ is the difference between a tool that gets used and one that gets ignored. Alert fatigue in cloud security is real, and I see it in almost every customer environment I work with.
  • Cross-team accountability: Getting Cloud, DevOps, and AppSec teams working from the same risk picture. This is as much an organisational challenge as a technical one, and having a shared, contextualised framework that each team can see their contribution to is something CISOs have been asking for. The lack of clear ownership is consistently cited as one of the biggest cloud security challenges and it is.
  • Continuous posture improvement: Tracking trends over time and knowing where your sensitive data actually lives PII, PHI, secrets, credentials. The Microsoft Gaming case study was a solid real-world example here: full governance across their AWS estate covering repositories, pipelines, identities, data, and runtime. That is a complex, large-scale proof point and it was convincing.

The technical maturity in the CNAPP sessions was noticeable. The framing has shifted from ‘we can detect this misconfiguration’ to ‘we can show you the complete attack path from a public-facing exposure to a critical data asset and quantify the business impact.’ That is a more useful conversation to be having.

 

Networking and Security Convergence: It Is Actually Happening

I have heard Fortinet talk about the convergence of networking and security for years. At previous events it felt like a positioning statement. At Accelerate 2026 it felt like operational reality  underpinned by customer outcome data I found credible: 65% reduction in network disruptions, 300% ROI through ASIC-accelerated performance, 50% productivity gains for teams running networking and security on the same platform. Those are the kind of numbers that get CFO attention.

FortiOS 8.0 makes this concrete at the OS level  a single operating system underpinning NGFW, IPS, SD-WAN, Wi-Fi, SASE, cloud security, and OT protection. The ASIC advantage matters here because it means hardware-level security acceleration without separate appliances or additional licensing. For organisations trying to consolidate their architecture without sacrificing performance, that is a meaningful differentiator.

The FortiEndpoint announcement also caught my attention  unifying ZTNA, SASE, EPP, EDR, and DLP into a single agent. Anyone who has dealt with the operational overhead of managing multiple competing endpoint agents on the same device will immediately understand why this matters.

 

 

My Honest Assessment

Not everything at every conference is groundbreaking, and I think you lose credibility quickly if you come back from a vendor event treating everything you heard as gospel. So here is where I genuinely landed.

What I Think Is Genuinely Strong

  • The AI-aware application inspection in FortiOS 8.0 solves a real, immediate problem that every enterprise security team I work with is navigating right now. Action-level policy control within AI applications is the right technical response to Shadow AI not blanket blocking.
  • FortiAIGate addresses a security gap that is growing faster than most teams have recognised. The organisations that build AI governance infrastructure now are making a smart investment.
  • The CNAPP story is materially more mature than twelve months ago. Lifecycle-spanning risk management with contextual exploitability rather than raw alert volume is where cloud security needs to go, and Fortinet is moving in that direction with real customer evidence.
  • The platform coherence is stronger than I expected. The announcements across networking, SecOps, endpoint, and cloud all tell the same story which is either excellent product strategy or very good conference messaging. Probably both.

Where I Still Have Questions

  • FortiSOC is a preview. I want to see it in production with real customer telemetry at scale before I get fully behind it. The architecture is right the execution is what will matter.
  • Agentic AI in SOC workflows raises important governance questions that the sessions touched on but did not fully address. When autonomous agents are making containment decisions, the audit trail and human oversight model needs to be clearly defined. I would want to understand that in depth before recommending it to a customer in a regulated environment.
  • FortiAIGate’s latency overhead in high-throughput AI inference environments needs real-world validation data. The GPU/SmartNIC acceleration is encouraging and the theory is sound but I would want to see benchmark data from customers running it at meaningful inference volumes before making architecture recommendations.
  • Sovereign SASE is promising for the specific customers it targets, but the operational model for managing the on-premises SASE Outpost alongside cloud policy management is something I would want to work through carefully for each specific deployment scenario.

 

Final Thoughts

I came away from Accelerate 2026 more impressed than I expected to be. Not because of any individual announcement  although FortiOS 8.0 and FortiAIGate both stand on their own  but because of the coherence of the overall story. Fortinet has a clear architectural position: converged networking and security, AI-augmented operations, lifecycle cloud protection, and a single platform that scales with the environment. That is a position built over 25 years and it shows.

For teams that have invested in the Fortinet platform, the roadmap gives a clear logical path forward. For teams evaluating whether to consolidate, Accelerate 2026 made the case more compellingly than any previous event I have attended. The specific innovations announced are concrete and practically useful  not aspirational slides.

The industry is in a genuinely important moment. Attackers have access to AI tools that compress the time between reconnaissance and impact from days to minutes. Defenders need platforms that operate at the same speed. Fortinet’s answer to that challenge is a unified, AI-native architecture  and from what I saw in Las Vegas, they are executing on it.

Martin Chapman

About the author

Martin is Forge’s CTO, shaping our technical strategy and leading solution design across services and delivery. With over 25 years in IT, he’s built and led expert teams for enterprise clients and spent the last decade developing large-scale cloud platforms for European and US markets. A passionate technology evangelist, Martin ensures our solutions are innovative, scalable, and aligned with client needs.

Related Articles

Building Resilience Across the UK Financial System: The Rise of Critical Third-Party Oversight

From 13 July 2026, UK financial regulators have taken a significant step to strengthen the resilience...

Community Innovation Becomes Industry Standard: The Next Chapter for Azure Landing Zones

Microsoft has announced that Azure Landing Zones (ALZ) will move from a community-led initiative into...

Elevating Endpoint Management with Microsoft Intune

From 1 July 2026, Microsoft has expanded Intune capabilities within Microsoft 365 E3 and E5 licences....

How can we help?

Considering a particular technology?
Got a question for our team?
Please get in touch, we’re here to help.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.