STOCK TITAN

Qualys Expands AI Security with Stronger Governance to Keep Fast Moving AI Adoption Under Control

(Neutral)
(Neutral)
Tags
AI

Qualys (NASDAQ: QLYS) announced new governance and security capabilities in its TotalAI solution, built on the Qualys Enterprise TruRisk Platform, to help organizations discover, test, monitor and govern enterprise AI risk from design to production.

TotalAI now lets CISOs reduce shadow AI, track AI agents, models, MCP servers and browser-based AI, apply TruRisk scoring to AI assets, shift AI security left into code and pipelines, and perform adversarial testing of LLMs and MCP servers. The product is generally available and aligned with emerging U.S. and EU safe-AI policy requirements.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

News Explained

The generally available additions make AI runtime activity, governance evidence, and MCP-server testing more directly observable.

Qualys says the newly announced TotalAI capabilities are generally available, adding kernel-level eBPF instrumentation for AI workloads and audit-ready evidence of governance performance.

The instrumentation is described as showing what AI workloads execute on servers, while the governance output records the AI assets, issue severity and impact, and a TruRisk-based plan for what to fix first.

The release also says TotalAI scans the MCP server itself, rather than only governing access to it, and tests LLMs and MCP servers for prompt injection, jailbreaks, unsafe output, tool poisoning, SSRF, and rug-pull risks.

Market Context

Historical AI reactions ranged from -3.43% to 4.05% over 24 hours, placing this TotalAI release with...
Analysis

Historical AI reactions ranged from -3.43% to 4.05% over 24 hours, placing this TotalAI release within a mixed platform record. Net Selling insider activity is a sourced risk; subsequent operating disclosures remain relevant.

Key Figures

Announcement date: July 29, 2026 Governance questions addressed: 4 questions OWASP framework: Top 10 +1 more
4 metrics
Announcement date July 29, 2026 TotalAI capabilities announcement
Governance questions addressed 4 questions TotalAI risk and governance capabilities
OWASP framework Top 10 LLM and MCP security risks
Black Hat booth #2333 Black Hat USA 2026

Previous AI Reports

5 past events · Latest: Mar 23 (Positive)
Same Type Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Mar 23 AI agent launch Positive +0.9% AI agent launched with reported remediation and exploit-validation capabilities
Oct 15 Agentic AI expansion Positive +0.1% Expanded agentic AI capabilities added across identity and exploit validation
Aug 04 AI platform launch Positive +4.0% Agentic AI risk operations center and autonomous remediation capabilities unveiled
Apr 29 TotalAI expansion Positive +1.7% TotalAI expanded with LLM testing and 40 attack scenarios
Aug 05 TotalAI introduction Positive -3.4% TotalAI introduced for generative AI and LLM security risks

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

AI-tagged announcements were followed by positive reactions in four of five comparable events, with one divergence and an average move of 0.68%.

Key Terms

shadow ai, model context protocol, ebpf, prompt injection, +1 more
5 terms
shadow ai technical
"Discover shadow AI, cloud AI services, AI agents, models, MCP servers"
Shadow AI describes employees using artificial intelligence tools or services without formal approval, oversight, or integration into official systems — for example, personal subscriptions, free web apps, or browser add-ons. For investors this matters because these hidden tools can expose sensitive data, create compliance or legal problems, produce unreliable results, and lead to unexpected costs or reputational damage, much like an unapproved gadget in a factory that creates safety and billing surprises.
model context protocol technical
"Model Context Protocol (MCP) servers onto security programs"
A model context protocol is a set of rules or guidelines that determine how a financial model interprets and applies information within a specific situation. It helps ensure consistent and accurate analysis by clarifying what data or assumptions are relevant in a given scenario. For investors, it provides clarity on how predictions or assessments are made, increasing confidence in decision-making.
ebpf technical
"Kernel-level (eBPF) instrumentation reveals what AI workloads execute"
eBPF (extended Berkeley Packet Filter) is a lightweight Linux technology that lets developers run small, safe programs inside the operating system to monitor, filter, or change how data moves and how services behave without changing the core software. For investors, eBPF matters because it can make cloud services and security tools faster, more flexible, and cheaper to operate, helping companies differentiate products and lower infrastructure costs.
prompt injection technical
"Test models for prompt injection, jailbreaks, and unsafe output"
A prompt injection is a deliberate attempt to trick an AI system by inserting misleading or malicious instructions into the text it reads, causing the system to behave in unintended ways or reveal sensitive information. Like slipping a fake note into a stack of instructions, it matters to investors because it can lead to data breaches, regulatory breaches, faulty decisions, reputational damage, and unexpected costs for companies that rely on AI-driven tools.
ssrf technical
"MCP servers (tool poisoning, SSRF, rug-pull)"
Server-Side Request Forgery (SSRF) is a web security flaw where an attacker tricks a company’s server into making network requests it shouldn’t, such as accessing internal systems, private data, or external services on the attacker’s behalf. Like convincing a trusted employee to fetch a sealed file from a locked room, SSRF can expose sensitive information, disrupt services, or lead to regulatory and reputation damage that may matter to investors monitoring operational and cyber risk.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

New capabilities in TotalAI enable CISOs to reduce shadow AI, flag abnormal model behavior, and prove controls are working across development and runtime

FOSTER CITY, Calif., July 29, 2026 /PRNewswire/ -- Qualys, Inc. (NASDAQ: QLYS), a leading provider of cloud-based IT, security and compliance solutions, today announced new capabilities in TotalAI, built on the Qualys Enterprise TruRisk Platform, to empower organizations to discover, test, monitor, and govern enterprise AI risk from design to production. TotalAI provides enterprise CISOs with robust AI governance and risk management capabilities that satisfy new policy requirements around safe AI use in the U.S. and EU.

Qualys TotalAI: AI Governance Dashboard

Enterprise AI adoption has outrun the controls built to govern it. Organizations are layering models, AI agents, and Model Context Protocol (MCP) servers onto security programs never designed for them, while attackers weaponize the same AI tools to move faster than defenders can track. Moreover, no other single point tool answers the questions security leaders face daily: Where is AI running? Which models can leak data or be manipulated? What are AI agents connected to? And can we prove our controls are working? TotalAI answers all four — with the same TruRisk score security teams already use for vulnerabilities, cloud, and containers.

"AI is outrunning the controls built to govern it, and security teams can no longer treat that risk as a separate list to be scanned and closed," said Grace Trinidad, Research Director at IDC. "The industry is moving beyond simply counting vulnerabilities toward continuously minimizing the exploitable surface, what is actually reachable and can be made to do harm, and AI is turning that shift from good practice to a requirement. Organizations that fold AI risk into continuous exposure management, spanning discovery, assessment, runtime visibility, and governance, will be the organizations positioned to adopt AI securely and at scale."

Qualys TotalAI provides enterprises with end-to-end AI security:

  • Gain total visibility into AI use — Discover shadow AI, cloud AI services, AI agents, models, MCP servers, AI containers, and browser-based AI, so teams know where AI runs across the enterprise and who owns the risk.
  • Govern agentic AI, models and integrations end to end — See and control the tool calls AI agents make over MCP, so an agent's reach can be contained if needed. Kernel-level (eBPF) instrumentation reveals what AI workloads execute on servers, delivering visibility that scanners and logs can't provide.
  • Prove governance is working — Give security, engineering, and governance, risk, and compliance (GRC) teams audit-ready evidence of what AI exists, the severity and impact of any issues, and a TruRisk-based prioritization plan of what to fix first.
  • Shift AI security left — Find AI vulnerabilities, misconfigurations, and exposed secrets earlier, in code and pipelines. Test models for prompt injection, jailbreaks, and unsafe output before they reach production.
  • Go beyond posture to adversarial testing — TotalAI red-teams both LLMs (prompt injection, jailbreaks) and MCP servers (tool poisoning, SSRF, rug-pull), mapped to the OWASP LLM & MCP Top 10 and the EU AI Act. While most tools govern MCP access, TotalAI scans the MCP server itself.

"With every modern enterprise leveraging AI, the question is changing from 'Is my AI secure?' to 'Can I prove it to my board and regulators?'" said Sumedh Thakar, president and CEO of Qualys. "TotalAI gives enterprises a single, unified way to assess, govern, and secure AI risk continuously — not through periodic snapshots, but with the real-time clarity and discipline Qualys is known for."

Availability
TotalAI is generally available. To learn more, visit qualys.com/free-trial-new/totalai or visit our booth #2333 at Black Hat USA 2026.

Additional Resources

About Qualys   
Qualys, Inc. (NASDAQ: QLYS) is a leading provider of cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

The Qualys Enterprise TruRisk Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Oracle Cloud Infrastructure, Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com.

Qualys, Qualys VMDR®, Qualys TruRisk and the Qualys logo are proprietary trademarks of Qualys, Inc. All other products or names may be trademarks of their respective companies. 

Media Contact:   
Rachel Yap Winship 
Qualys
Media@Qualys.com

Qualys, Inc., Redwood City, Calif.

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/qualys-expands-ai-security-with-stronger-governance-to-keep-fast-moving-ai-adoption-under-control-302837084.html

SOURCE Qualys, Inc.

FAQ

What did Qualys (NASDAQ: QLYS) announce about TotalAI on July 29, 2026?

Qualys announced expanded TotalAI capabilities to govern AI risk across design and production. According to Qualys, TotalAI now discovers, tests, monitors and governs enterprise AI, helping CISOs address shadow AI, AI agents, models, MCP servers and browser-based AI in one platform.

How does Qualys TotalAI help reduce shadow AI risk for enterprises using QLYS solutions?

TotalAI helps reduce shadow AI by discovering cloud AI services, AI agents, models, MCP servers, containers and browser-based AI. According to Qualys, this visibility lets teams see where AI runs, who owns associated risk, and integrate AI assets into existing TruRisk-based security programs.

How does Qualys TotalAI support AI governance and regulatory requirements in the U.S. and EU?

TotalAI provides AI governance and risk management that Qualys says satisfies new safe-AI policy requirements in the U.S. and EU. It offers audit-ready evidence of AI assets, issue severity, impact, and TruRisk-based remediation plans, supporting boards, regulators and GRC teams overseeing AI deployments.

What AI security testing features are included in Qualys TotalAI for QLYS customers?

According to Qualys, TotalAI tests models for prompt injection, jailbreaks and unsafe output before production and red-teams both LLMs and MCP servers. It maps tests to the OWASP LLM & MCP Top 10 and the EU AI Act, extending security beyond configuration posture checks.

How does Qualys TotalAI give runtime visibility into AI agents, MCP servers and workloads?

TotalAI governs agentic AI by monitoring tool calls AI agents make over MCP and allowing containment. According to Qualys, kernel-level eBPF instrumentation reveals executed AI workloads on servers, providing runtime visibility that traditional scanners and log-based approaches may not capture effectively.

Is Qualys TotalAI generally available and how can organizations try it?

TotalAI is generally available as part of the Qualys Enterprise TruRisk Platform. According to Qualys, organizations can learn more, request a demo, or start via a trial at qualys.com/free-trial-new/totalai, and engage further at Black Hat USA 2026 or through scheduled meetings and webinars.