Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Vijil's DART red-teams enterprise AI agents with adaptive attacker agents

Vijil released DART, which tests enterprise AI agents with its own multi-turn attacker agents and claims 1.5 times a rival's attack success rate. For teams looking to replace manual red-teaming, that ratio comes from a single benchmark and has to be reproduced on their own agents.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Vijil's DART red-teams enterprise AI agents with adaptive attacker agents
Generated illustration

What happened

  • DART attacks the whole agent, including its tool use, memory and multi-turn behavior, inside the agent's own environment.
  • In the DecodingTrust-Agent evaluation, DART beat its closest competitor in nine of twelve enterprise agent tasks across domains such as CRM, code, medical and travel.
  • It deploys through APIs into CI/CD pipelines and runs under sustained load with rate limiting, retries and per-role model configuration.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Because DART exercises tool use in the target's own environment, owners have to decide before the first run which environment and which tool permissions the attacker agents can reach.
  • capability Red-team runs can sit in the build pipeline and repeat on each change, replacing a single consultant engagement booked shortly before launch.
  • capability Regulated and air-gapped shops can run adversarial testing inside their own VPC or on-prem without sending agent traffic to a vendor's cloud.

Gartner's two figures put the growth at more than 10,000-fold in three years for an average global Fortune 500 company [12]. Vijil says AI engineering and governance teams have neither the bandwidth nor the budget to test that many agents by hand [13]. The forecast is Gartner's [3]. The threat claim is Vijil's: according to the company, threat actors are increasingly deploying their own agents to run sustained, multi-turn attacks against enterprise AI systems [14].

Vijil's case against existing tools is specific. It says they try to match the pattern of known attacks [20]. Most, it says, check an agent's output against a static set of prompts and test only the language model and the chat interface [15]. DART runs several attacker agents of its own, and their tactics adapt across turns, episodes and engagements [2]. It scores each response, adjusts and retries as many times as the user sets [5]. According to Vijil, it finds vulnerabilities without being told what to look for [5]. Risk coverage starts from taxonomies based on OWASP, MITRE and Vijil research, and can be rebuilt from an enterprise's own risk catalog [6].

The evidence offered for the adaptive approach is one evaluation on the DecodingTrust-Agent benchmark, where DART's attack success rate was 1.5 times its closest competitor's [16]. The announcement does not name that competitor or give either system's absolute success rate [11]. A buyer cannot get from the ratio to how many attacks actually landed [11]. In three of the twelve tasks, the competitor matched or beat DART [21].

"There's a big gap between an agent that appears ready in a demo and one that proves its reliability, security, and safety under pressure," said Vin Sharma, Vijil's CEO [18]. He said DART closes it, "saving weeks of effort and tens of thousands of dollars compared to manual red-teaming engagements, generic benchmarks, and open source prototypes" [19].

DART is a new capability of Vijil Diamond [1]. After it reports, other Vijil modules run root-cause analysis, add policy-driven guardrails and suggest code changes, so the finding and the proposed fix come from one vendor [9]. Another module, Vijil Discover, finds and fingerprints agents wherever they run, including shadow AI [10].

What to watch

  • An independent DecodingTrust-Agent run that names the competitor and publishes absolute attack success rates for both systems.
  • Incident reporting that ties a named threat actor to sustained multi-turn agent attacks on enterprise AI systems, which would move Vijil's threat claim onto the record.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence25
Adoption
Insufficient
Hype gap+45
Incentives85
Confidence35
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Vijil released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations in enterprise AI agents; DART is a new capability of Vijil Diamond.

    ReportedSupportedSource: Help Net Security, reporting Vijil's announcementView cited source
  2. [2]

    DART employs multiple adversarial agents of its own to probe the target's defenses with multi-turn attacks that learn and adapt tactics across turns, episodes, and engagements.

    ReportedSupportedSource: Vijil, via Help Net SecurityView cited source
  3. [3]

    Gartner estimates that an average global Fortune 500 company will be using more than 150,000 agents by 2028, compared to fewer than 15 in 2025.

    ReportedSupportedSource: Gartner estimate, cited in Help Net SecurityView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · October 7, 2026

    Vijil DART tests AI agents for security flaws and policy violations

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories