Qualys, the cloud-based IT, security and compliance solutions organisation has announced new capabilities in TotalAI. The solution helps CISOs with robust AI governance and risk management capabilites that work according to the new policy framework requirements of safe AI use across the US and EU.
Built on the existing Qualys Enterprise TruRisk platform, the new expanded capabilities help organisations test, discover, monitor and govern enterprise AI risk from design to production.
“With every modern enterprise leveraging AI, the question is changing from ‘Is my AI secure?’ to ‘Can I prove it to my board and regulators?’,” said Sumedh Thakar, president and CEO of Qualys in a press statement shared by the company.
Thakar explained, “TotalAI gives enterprises a single, unified way to assess, govern, and secure AI risk continuously — not through periodic snapshots, but with the real-time clarity and discipline Qualys is known for.”
Currently, the adoption of enterprise AI is outpacing the controls that need to govern it, most organisations end up layering models, Model Context Protocol (MCP) servers, AI agents on existing security programmes that weren’t designed for them. The challenge is that attackers weaponise the same AI tools to move faster than what defenders can track.
Grace Trinidad, Research Director at IDC, stated in the press note, “AI is outrunning the controls built to govern it, and security teams can no longer treat that risk as a separate list to be scanned and closed.” Trinidad explained, the industry now is moving at a pace that goes beyond counting vulnerabilities toward continuously minimising the exploitable surface. She added what is actually reachable can be made to do harm, and AI is turning the shift from a good practice to a necessity.
Moreover, no other single point tool answers the questions security leaders face daily: Where is AI running? Which models can leak data or be manipulated? What are AI agents connected to? And can we prove our controls are working? TotalAI answers all four — with the same TruRisk score security teams already use for vulnerabilities, cloud, and containers.
TotalAI helps discover shadow AI, cloud AI services, AI agents, models, MCP servers, AI containers, and browser-based AI, so teams know where AI runs across the enterprise and who owns the risk. It also helps govern agentic AI models and integrations end-to-end by seeing and controlling the tool calls AI agents make over MCP, so an agent’s reach can be contained if needed.
The focus is to shift AI security towards finding AI vulnerabilities, misconfigurations, and exposed secrets earlier, in code and pipelines. It also helps test models for prompt injection, jailbreaks, and unsafe output before they reach production.
Kernel-level (eBPF) instrumentation reveals what AI workloads execute on servers, delivering visibility that scanners and logs can’t provide. TotalAI also gives security, engineering, and governance, risk, and compliance (GRC) teams audit-ready evidence of what AI exists, the severity and impact of any issues, and a TruRisk-based prioritisation plan of what to fix first.
As the need and pace for AI security is growing, number of security providers and vendors are building solutions and products that help bring existing measures upto the pace needed in an AI-native world.





