What happened
Qualys announced (July 29, 2026) general availability of new TotalAI capabilities on its Enterprise TruRisk Platform, adding kernel-level eBPF instrumentation for AI workload runtime visibility, MCP-server adversarial testing (prompt injection, tool poisoning, SSRF, rug-pull risks mapped to OWASP LLM/MCP Top 10), and audit-ready governance evidence for shadow AI, agents, and models.
Why it matters
Addresses the 'evidence gap' in AI governance by combining code-to-runtime security scanning with adversarial LLM/MCP testing in a single GA product from an established vulnerability-management vendor, aligning with EU AI Act/US policy requirements.
Applicability
CISOs needing audit-ready proof of AI control effectiveness for regulators/boards should evaluate TotalAI now; especially relevant for organizations with existing Qualys TruRisk deployments.