FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Article Id 196665

This article describes that if firewall policy is set to flow-mode inspection, it wil not be possible to apply web filter or antivirus profile to it. 

This is because both Antivirus and web filter by default will be created with Feature-set in Proxy. 
In those cases, the profile will not be visible in the drop-down menu.
Go to Security Profiles -> Web Filter, select the profile and next to 'Feature set', select 'Flow-based' and then select 'OK'.
Go back to the Policy page and the web filter profile 'test' in this example, can be selected in the web filter drop-down menu.