Qualys has expanded the capabilities of TotalAI, its AI security offering built on the Qualys Enterprise TruRisk Platform, adding new tools to help organisations discover, assess, monitor and govern AI risk across development and production environments.
The update is designed to provide organisations with greater visibility into AI deployments, including AI agents, models, cloud AI services, Model Context Protocol (MCP) servers, AI containers and browser-based AI applications. Qualys said the new capabilities also support compliance with emerging AI governance requirements in the United States and the European Union.
According to the company, TotalAI enables organisations to identify AI vulnerabilities, misconfigurations and exposed secrets earlier in the software development process, while also testing large language models for prompt injection, jailbreaks and unsafe outputs before deployment. The platform also adds adversarial testing for MCP servers and provides runtime visibility into AI workloads using kernel-level instrumentation.
“AI is outrunning the controls built to govern it, and security teams can no longer treat that risk as a separate list to be scanned and closed,” said Grace Trinidad, Research Director at IDC. “The industry is moving beyond simply counting vulnerabilities toward continuously minimizing the exploitable surface, what is actually reachable and can be made to do harm, and AI is turning that shift from good practice to a requirement.”
Qualys said the platform also gives security, engineering and governance teams visibility into AI assets and prioritises risks using its TruRisk scoring model.
“With every modern enterprise leveraging AI, the question is changing from ‘Is my AI secure?’ to ‘Can I prove it to my board and regulators?’,” said Sumedh Thakar, President and CEO of Qualys. “TotalAI gives enterprises a single, unified way to assess, govern, and secure AI risk continuously — not through periodic snapshots, but with the real-time clarity and discipline Qualys is known for.”






Discussion about this post