Tami Casey put it in five words at the Qualys booth: we want to be the solution and not the fear. On a Black Hat floor built on black hoodies, red neon, and breach counters, Qualys ran a white booth. That contrast was the pitch before anyone said a word.
Rupa Ravuri walked me through a live demo of TotalAI, the platform Qualys expanded with new governance capabilities on July 29 and pushed to general availability this week at Black Hat USA 2026. Kailash Singh, Qualys's senior manager of analyst relations, joined partway through. I have covered Qualys before, most recently the Agent Val launch inside Enterprise TruRisk Management this spring, and the throughline held: this is a company that keeps bolting new functionality onto one risk backbone rather than shipping disconnected point products.
White Was the Loudest Color on the Floor
Most AI security vendors at Black Hat sell on threat volume. More CVEs, more jailbreak attempts, more shadow tools than you can count. Qualys chose the opposite visual register, and Casey named the reasoning directly rather than leaving it implied. The company wants CISOs walking away thinking about what gets fixed, not what got found.
That framing only works if the product backs it up.
Four Pillars, Straight From the Release
Qualys built the July 29 expansion around four connected pieces: discovery, assessment, remediation, and governance. Discovery means finding sanctioned and shadow artificial intelligence across cloud services, GPUs, containers, code repositories, software as a service copilots, browser extensions, agents, and Model Context Protocol servers, the connective layer that lets AI agents call outside tools. Assessment combines posture scanning with adversarial testing of large language models and MCP servers for prompt injection, jailbreaks, and tool poisoning, plus runtime monitoring built on eBPF, a kernel-level instrumentation technique that watches what an AI workload actually executes on a server. Remediation scores every finding through the TruRisk engine and routes it to the team that owns the fix. Governance exports the whole trail as reports mapped to frameworks like the NIST AI Risk Management Framework and the EU AI Act.
The Demo Followed the Same Order
Ravuri opened with inventory: deploy the Qualys agent once, and it returns a count of GPUs, software, and AI assets across the environment without additional configuration. From there she pulled up the model registry, which flags policy mismatches on sight. Her example: an organization that authorizes one large language model internally still shows employees calling a different one for image generation, a gap the registry surfaces automatically rather than waiting for a self-report.
Code repository scanning came next. TotalAI flagged an outdated Python version and traced the finding down to the specific container and image running it, not just the repository it came from. A separate module handles application programming interface scanning, and another covers web application testing, both of which have to be enabled individually rather than turning on with the base agent.
The part that got the most attention from the small crowd around the booth was browser-level shadow AI detection: TotalAI catches an employee using a personal laptop to run an AI tool the company never approved, then classifies it as a shadow asset the same way it would an unpatched server.
Two capabilities are still on the roadmap rather than shipped. One blocks an employee from pasting personally identifiable information into an AI tool in real time, with the sensitivity rules set by the customer. The other extends network-level monitoring to trace where AI-related data actually travels once it leaves a browser or an agent. Ravuri described both as close, not live.
This Extends a Pattern, Not a Pivot
Set next to Agent Val, the exploit validation agent Qualys introduced inside Enterprise TruRisk Management in March, TotalAI reads less like a new product line and more like the same TruRisk backbone extending into a new risk category. Agent Val proved which vulnerabilities were actually exploitable. TotalAI applies that same instinct, evidence over inventory, to artificial intelligence specifically. For a company two decades into vulnerability management, adding AI governance onto an existing scoring engine is a lower-risk move than most of the AI security floor is attempting.
"We want to be the solution and not the fear."
Tami Casey, Qualys
Qualys is betting that security buyers will pay for proof over another detection dashboard. Before the next renewal cycle, ask your team to pull one TotalAI finding, a flagged shadow model or a failed jailbreak test, and walk it in front of your auditor. If the evidence holds up unchanged, the bet is paying off. If it needs translation first, TotalAI is still a scanner with better packaging.
Sources: Qualys, Inc. "Operationalize AI Governance Across Shadow GenAI, MCP, and Agentic Workloads with Qualys TotalAI." Qualys Blog, 29 July 2026, blog.qualys.com/product-tech/2026/07/29/ai-governance-evidence-gap-totalai. OWASP GenAI Security Project. "State of Agentic AI Security and Governance," version 2.01. OWASP, 11 June 2026, genai.owasp.org. Bellamkonda, Shashi. "Meet Agent Val: Qualys Closes the Validation Gap in Exposure Management with Agentic AI." shashi.co, March 2026, www.shashi.co/2026/03/meet-agent-val-qualys-closes-validation.html. Demo and interview: Rupa Ravuri and Kailash Singh, Qualys, Black Hat USA 2026, Mandalay Bay, Las Vegas, 5 August 2026.

