Vijil DART Tests Enterprise AI Agents With Adaptive Red Teaming
Help Net Security reported that Vijil released DART, an adaptive red-teaming system that uses adversarial agents to test enterprise AI agents across tools, memory and multi-turn behavior.

Vijil has moved AI-agent red teaming into an adaptive test pattern, Help Net Security reported, with a new DART system that uses adversarial agents to probe security flaws and policy violations across enterprise agents.
The product, formally Diamond Adaptive Red Teaming for Agents, is designed to test more than a model prompt or chat interface.
Its attacks run across tool use, memory and multi-turn behavior, then adjust tactics as the target agent responds.
Those are the same functions that can turn a chatbot-style risk into an operational security problem when an agent has enterprise permissions.
That makes the release a security-control story rather than a simple product update: Vijil is positioning DART as a way to stress agents inside the same operating conditions where they may make decisions or handle sensitive data.
The pressure behind that approach is scale.
Gartner estimates that a typical global Fortune 500 company will use more than 150,000 agents by 2028, compared with fewer than 15 in 2025.
Manual testing would struggle to keep pace with that increase, while attackers can also deploy agents for sustained, multi-turn campaigns against enterprise AI systems.
Static Prompts Are The Baseline DART Tries To Move Past
Existing red-teaming tools check agent output against known attack patterns and static prompt sets.
That approach can miss new strategies, does not fully exercise agent behavior across tools and memory, and often enters the development process late through outside consulting engagements.
When serious findings arrive days before launch, developers may have little time to change code, policies or deployment plans.
DART changes the control path by running waves of attacks that learn across turns, episodes and engagements.
The system evaluates the target response, changes its approach and retries for as many rounds as the user specifies.
It can begin testing without a predefined vulnerability list, which is the main distinction from fixed-script prompt libraries.
Benchmark Result Gives The Release Its Evidence Point
Vijil cites a DecodingTrust-Agent benchmark evaluation in which DART achieved an attack success rate 1.5 times that of its closest competitor.
The system surpassed that competitor in nine of twelve enterprise agent tasks.
The evaluated tasks covered CRM, software coding, support, healthcare, research workflows and travel scenarios.
Those figures should be read as vendor-provided benchmark evidence, not an independent security certification.
Still, they define the claim Vijil is making: adaptive red teaming can uncover more agent weaknesses than static prompt testing when enterprise tasks require multi-step behavior.
Vin Sharma, Vijil’s CEO, framed the issue around agents that can reach confidential data and take consequential action.
He presented DART as a way to reduce long testing cycles and large engagement costs when teams compare it with consultant-led red teaming, broad benchmarks or prototype toolkits.
DART is part of Vijil Diamond inside the broader Vijil platform.
After DART identifies weaknesses, other modules perform root-cause analysis, apply policy-driven guardrails and suggest code changes.
The surrounding platform also includes Discover for finding and fingerprinting agents, Dome for production policy compliance and Darwin for continuous improvement as users, models and attack methods change.




















