Qualys expands TotalAI with governance tools for enterprise AI risk

By Staff Writer on Sep 30, 2026 3:39PM
Qualys expands TotalAI with governance tools for enterprise AI risk
Sumedh Thakar, Qualys.
Supplied

In summary

  • Qualys has expanded TotalAI, built on the Qualys Enterprise TruRisk Platform, to discover, test, monitor and govern AI risk from development through to production.
  • New discovery features include shadow AI, cloud AI services, AI agents, AI containers and browser-based AI, plus eBPF-based kernel-level instrumentation and MCP tool-call visibility.
  • Adversarial red-teaming now covers LLMs and MCP servers, mapped to the OWASP LLM and MCP Top 10 and the EU AI Act, with TruRisk-based prioritisation of remediation.

Qualys has added new capabilities to its TotalAI product, built on the Qualys Enterprise TruRisk Platform, aimed at helping enterprises discover, test, monitor and govern AI risk from development through to production.

TotalAI extends the TruRisk scoring system Qualys customers already use for vulnerabilities, cloud and containers to cover AI-specific risk. The additions include discovery of shadow AI, cloud AI services, AI agents, AI containers and browser-based AI, giving security teams visibility into where AI runs across the enterprise and who owns the associated risk.

The platform now offers kernel-level instrumentation using eBPF to reveal what AI workloads are executing on servers - visibility the company said scanners and logs cannot provide. It also covers tool calls that AI agents make over MCP, allowing teams to contain an agent's reach if needed.

On the testing side, TotalAI adds adversarial red-teaming for both large language models (LLMs) - covering prompt injection and jailbreaks - and MCP servers, including tool poisoning, server-side request forgery (SSRF) and rug-pull attacks. Qualys said the capability is mapped to the OWASP LLM and MCP Top 10 and the EU AI Act.

The platform also aims to help security, engineering and governance, risk, and compliance (GRC) teams produce audit-ready evidence of AI assets and issues, with TruRisk-based prioritisation of remediation.

"With every modern enterprise leveraging AI, the question is changing from 'Is my AI secure?' to 'Can I prove it to my board and regulators?'" said Sumedh Thakar, president and chief executive at Qualys.

"TotalAI gives enterprises a single, unified way to assess, govern, and secure AI risk continuously — not through periodic snapshots, but with the real-time clarity and discipline Qualys is known for."

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?