Security1 publisherNot yet confirmed elsewhere2 min readPublished
Vijil's DART red-teams enterprise AI agents with adaptive attacker agents
Vijil released DART, which tests enterprise AI agents with its own multi-turn attacker agents and claims 1.5 times a rival's attack success rate. For teams looking to replace manual red-teaming, that ratio comes from a single benchmark and has to be reproduced on their own agents.
The Watch · Security desk

What happened
- DART attacks the whole agent, including its tool use, memory and multi-turn behavior, inside the agent's own environment.
- In the DecodingTrust-Agent evaluation, DART beat its closest competitor in nine of twelve enterprise agent tasks across domains such as CRM, code, medical and travel.
- It deploys through APIs into CI/CD pipelines and runs under sustained load with rate limiting, retries and per-role model configuration.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Because DART exercises tool use in the target's own environment, owners have to decide before the first run which environment and which tool permissions the attacker agents can reach.
- capability Red-team runs can sit in the build pipeline and repeat on each change, replacing a single consultant engagement booked shortly before launch.
- capability Regulated and air-gapped shops can run adversarial testing inside their own VPC or on-prem without sending agent traffic to a vendor's cloud.
Gartner's two figures put the growth at more than 10,000-fold in three years for an average global Fortune 500 company [12]. Vijil says AI engineering and governance teams have neither the bandwidth nor the budget to test that many agents by hand [13]. The forecast is Gartner's [3]. The threat claim is Vijil's: according to the company, threat actors are increasingly deploying their own agents to run sustained, multi-turn attacks against enterprise AI systems [14].
Vijil's case against existing tools is specific. It says they try to match the pattern of known attacks [20]. Most, it says, check an agent's output against a static set of prompts and test only the language model and the chat interface [15]. DART runs several attacker agents of its own, and their tactics adapt across turns, episodes and engagements [2]. It scores each response, adjusts and retries as many times as the user sets [5]. According to Vijil, it finds vulnerabilities without being told what to look for [5]. Risk coverage starts from taxonomies based on OWASP, MITRE and Vijil research, and can be rebuilt from an enterprise's own risk catalog [6].
The evidence offered for the adaptive approach is one evaluation on the DecodingTrust-Agent benchmark, where DART's attack success rate was 1.5 times its closest competitor's [16]. The announcement does not name that competitor or give either system's absolute success rate [11]. A buyer cannot get from the ratio to how many attacks actually landed [11]. In three of the twelve tasks, the competitor matched or beat DART [21].
"There's a big gap between an agent that appears ready in a demo and one that proves its reliability, security, and safety under pressure," said Vin Sharma, Vijil's CEO [18]. He said DART closes it, "saving weeks of effort and tens of thousands of dollars compared to manual red-teaming engagements, generic benchmarks, and open source prototypes" [19].
DART is a new capability of Vijil Diamond [1]. After it reports, other Vijil modules run root-cause analysis, add policy-driven guardrails and suggest code changes, so the finding and the proposed fix come from one vendor [9]. Another module, Vijil Discover, finds and fingerprints agents wherever they run, including shadow AI [10].
What to watch
- An independent DecodingTrust-Agent run that names the competitor and publishes absolute attack success rates for both systems.
- Incident reporting that ties a named threat actor to sustained multi-turn agent attacks on enterprise AI systems, which would move Vijil's threat claim onto the record.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence25
- Adoption
- Insufficient
- Hype gap+45
- Incentives85
- Confidence35
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Vijil released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations in enterprise AI agents; DART is a new capability of Vijil Diamond.
- [2]
DART employs multiple adversarial agents of its own to probe the target's defenses with multi-turn attacks that learn and adapt tactics across turns, episodes, and engagements.
- [3]
Gartner estimates that an average global Fortune 500 company will be using more than 150,000 agents by 2028, compared to fewer than 15 in 2025.
- [4]
DART tests the whole agent, including its tool-use, memory, and multi-turn behavior, using attacks that adapt to the target agent in its own environment.
- [5]
DART evaluates the agent's response, adjusts its tactics, and retries as many times as the user specifies; Vijil says it doesn't need to be told what vulnerabilities to look for.
- [6]
DART ships with predefined risk taxonomies based on OWASP, MITRE, and Vijil research, but coverage can be derived from any enterprise-specific risk catalog.
- [7]
DART runs automatically at scale under sustained load, with rate limiting, retries, and per-role model configuration, and is deployable via APIs as part of an AI team's CI/CD process.
- [8]
DART runs in a customer's own VPC or fully on-prem, in air-gapped and regulated environments.
- [9]
After DART identifies agentic weaknesses, other modules of the Vijil platform perform root-cause analysis, implement policy-driven guardrails, and suggest code changes to fix the issues.
- [10]
Vijil Discover finds and fingerprints agents wherever they are, including shadow AI.
- [11]
The announcement identifies the comparison system only as DART's 'closest competitor' and reports the DecodingTrust-Agent result as a ratio, without absolute attack success rates for either system.
- [12]
Gartner's estimates imply per-company agent counts grow more than 10,000-fold between 2025 and 2028 for an average global Fortune 500 company.
- [13]
AI engineering and AI governance teams don't have the bandwidth or the budget to test all these agents by hand.
- [14]
Threat actors are increasingly deploying their own agents to launch sustained, multi-turn attacks against enterprise AI systems.
ReportedInsufficientSource: Vijil, via Help Net Security; no incident or actor citedView cited source - [15]
Most existing red-teaming tools do little more than check an agent's output against a static set of attack prompts; they test the language model and the chat interface, and run under supervision by external consultants outside the agent development lifecycle, often only days before deployment.
- [16]
In a recent evaluation using the DecodingTrust-Agent benchmark, DART achieved an attack success rate 1.5 times that of its closest competitor.
- [17]
DART surpassed the competitor's results in nine of twelve enterprise agent tasks spanning domains including CRM, code, customer service, medical, research, and travel.
- [18]
"There's a big gap between an agent that appears ready in a demo and one that proves its reliability, security, and safety under pressure."
- [19]
"DART closes that gap, saving weeks of effort and tens of thousands of dollars compared to manual red-teaming engagements, generic benchmarks, and open source prototypes."
- [20]
Existing red-teaming tools try to match the pattern of known attacks but fail to keep up.
- [21]
In three of the twelve DecodingTrust-Agent tasks, DART did not surpass its closest competitor, meaning the competitor matched or beat it.
Sources
1 independent publisher whose own reporting we read for this story.
- helpnetsecurity.comVijil DART tests AI agents for security flaws and policy violations
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- VijilFollow
- Diamond Adaptive Red Teaming for AgentsFollow
- Vin SharmaFollow
- Gartner Inc.Follow
- DecodingTrust-AgentFollow
- OWASPFollow
- The MITRE CorporationFollow