28.8 C
Casper
Friday, September 4, 2026

Qualys Adds AI Governance Tools to Curb Shadow AI Risk

spot_img

Must read

As AI adoption outpaces governance, Qualys says its expanded TotalAI platform gives security teams a way to prove their controls actually work.

Qualys, Inc., a provider of cloud-based IT, security and compliance solutions, announced new capabilities in TotalAI, built on the Qualys Enterprise TruRisk Platform, designed to help organizations discover, test, monitor and govern enterprise AI risk from design through production. The company says TotalAI gives enterprise CISOs the AI governance and risk management capabilities needed to meet emerging policy requirements around safe AI use in the U.S. and EU.

Enterprise AI adoption has outpaced the controls built to govern it, according to Qualys. Organizations are layering models, AI agents and Model Context Protocol (MCP) servers onto security programs that weren’t designed for them, while attackers use the same AI tools to move faster than defenders can track. Qualys says no single existing tool answers four questions security leaders now face daily: Where is AI running? Which models can leak data or be manipulated? What are AI agents connected to? And can organizations prove their controls are working? TotalAI is designed to address all four, using the same TruRisk scoring system security teams already use for vulnerabilities, cloud and container risk.

“AI is outrunning the controls built to govern it, and security teams can no longer treat that risk as a separate list to be scanned and closed,” said Grace Trinidad, research director at IDC. “The industry is moving beyond simply counting vulnerabilities toward continuously minimizing the exploitable surface — what is actually reachable and can be made to do harm — and AI is turning that shift from good practice into a requirement. Organizations that fold AI risk into continuous exposure management, spanning discovery, assessment, runtime visibility and governance, will be the ones positioned to adopt AI securely and at scale.”

Also Read: The Hidden Cost of AI Adoption Without a Plan

Qualys TotalAI is designed to provide enterprises with end-to-end AI security:

  • Total visibility into AI use. Discovers shadow AI, cloud AI services, AI agents, models, MCP servers, AI containers and browser-based AI, so teams can see where AI runs across the enterprise and who owns the associated risk.
  • End-to-end governance of agentic AI, models and integrations. Shows and controls the tool calls AI agents make over MCP, allowing an agent’s reach to be contained when needed. Kernel-level (eBPF) instrumentation reveals what AI workloads actually execute on servers — visibility Qualys says scanners and logs alone can’t provide.
  • Audit-ready proof of governance. Gives security, engineering and governance, risk and compliance (GRC) teams evidence of what AI exists, the severity and impact of any issues, and a TruRisk-based plan for prioritizing fixes.
  • AI security shifted left. Surfaces AI vulnerabilities, misconfigurations and exposed secrets earlier in code and pipelines, and tests models for prompt injection, jailbreaks and unsafe output before they reach production.
  • Adversarial testing beyond posture checks. TotalAI red-teams both large language models (prompt injection, jailbreaks) and MCP servers (tool poisoning, SSRF, rug-pull attacks), mapped to the OWASP LLM and MCP Top 10 and the EU AI Act. While Qualys says most tools govern MCP access, TotalAI scans the MCP server itself.

“With every modern enterprise leveraging AI, the question is changing from ‘Is my AI secure?’ to ‘Can I prove it to my board and regulators?'” said Sumedh Thakar, president and CEO of Qualys. “TotalAI gives enterprises a single, unified way to assess, govern and secure AI risk continuously — not through periodic snapshots, but with real-time clarity and discipline.”

spot_img

More articles

spot_img

Latest posts