Qualys has announced new capabilities for its TotalAI product, adding features it says are designed to help organisations govern and manage AI risk from development through to production use.
The company said the update is intended to help chief information security officers identify and control “shadow AI”, monitor model behaviour, and produce evidence that controls are operating across both development and runtime environments. TotalAI is built on the Qualys Enterprise TruRisk Platform, according to the company.
The announcement comes as security teams face growing pressure to track how AI is being deployed across organisations, including the use of AI agents and associated integrations. Qualys said TotalAI is intended to answer operational questions such as where AI is running, which models could expose data or be manipulated, what AI agents are connected to, and whether controls are effective, using a TruRisk score the company also applies to other areas such as vulnerabilities, cloud and containers.
“AI is outrunning the controls built to govern it, and security teams can no longer treat that risk as a separate list to be scanned and closed,” said Grace Trinidad, Research Director at IDC. “The industry is moving beyond simply counting vulnerabilities toward continuously minimising the exploitable surface, what is actually reachable and can be made to do harm, and AI is turning that shift from good practice to a requirement. Organisations that fold AI risk into continuous exposure management, spanning discovery, assessment, runtime visibility, and governance, will be the organisations positioned to adopt AI securely and at scale.”
Qualys said TotalAI includes discovery of AI usage across environments, including cloud AI services, AI agents, models, Model Context Protocol (MCP) servers, AI containers and browser-based AI. It also said the product provides governance controls over AI agents’ tool calls made via MCP, and uses kernel-level eBPF instrumentation to identify AI workloads executing on servers.
The company said TotalAI can provide “audit-ready” reporting intended to support governance, risk and compliance (GRC) requirements, and includes capabilities to find AI-related vulnerabilities, misconfigurations and exposed secrets earlier in software development pipelines. It also said the tool supports adversarial testing of large language models and MCP servers, mapped to the OWASP LLM & MCP Top 10 and the EU AI Act.
“With every modern enterprise leveraging AI, the question is changing from ‘Is my AI secure?’ to ‘Can I prove it to my board and regulators?’” said Sumedh Thakar, president and CEO of Qualys. “TotalAI gives enterprises a single, unified way to assess, govern, and secure AI risk continuously — notthrough periodic snapshots, but with the real-time clarity and discipline Qualys is known for.”
Qualys said TotalAI is generally available.

