Vijil DART red-teams AI agents with adaptive attacks

Vijil DART red-teams AI agents with adaptive attacks

Vijil has launched Diamond Adaptive Red Teaming for Agents (DART), an automated system that searches enterprise AI agents for security vulnerabilities and policy violations. DART does not fire a fixed list of prompts at its target. It deploys several adversarial agents of its own, which run multi-turn attacks and change their tactics as they learn.

The company says AI developers and application security engineers can use DART to uncover more problems across their agent fleets than they would find with red-team tools and services built on static test prompts.

The scale problem

Vijil points to a Gartner estimate as the reason for the launch. By 2028, the average global Fortune 500 company is expected to run more than 150,000 agents. In 2025 the figure was fewer than 15. AI engineering and governance teams lack the time and money to test that many agents by hand.

Attackers are moving in the same direction. Threat actors are increasingly using their own AI agents to run sustained, multi-turn attacks against enterprise AI systems.

According to Vijil, current red-teaming tools mostly try to match known attack patterns and struggle to keep up. They rarely come up with new ways to get around an agent's defenses. Many simply compare an agent's output against a static set of attack prompts, and they cover only the language model and the chat interface.

Timing is another problem. These tests are often run by external consultants, outside the agent development lifecycle, sometimes only days before launch. That leaves developers little room to fix serious findings before the agent goes live.

How DART works

DART tests the whole agent, including tool use, memory and behavior across multiple turns. Its attacks adapt to the target in the target's own environment. The system sends out waves of multi-turn attacks, evaluates each response, adjusts its approach and tries again, as many times as the user sets.

It does not need a list of vulnerabilities to look for. Vijil says it finds them by itself.

The main features include:

  • Risk coverage: Predefined taxonomies based on OWASP, MITRE and Vijil's own research, with the option to build coverage from an enterprise's own risk catalog.
  • Attack chaining: Attacks are chained across turns and episodes to map the attack surface and exploit weak points.
  • Developer tooling: A plugin for coding agents such as Claude Code and Codex. DART works with any agent framework or deployment platform and produces an auditable report for both engineering and compliance teams.
  • DevOps workflow: Automated runs at scale under sustained load, with rate limiting, retries and per-role model configuration. It can be called through APIs as part of a CI/CD pipeline.
  • Deployment options: It can run in a customer's own VPC or fully on-premises, including air-gapped and regulated environments.

Benchmark results

In a recent test on the DecodingTrust-Agent benchmark, DART reached an attack success rate 1.5 times higher than its closest competitor. It beat that competitor in nine of twelve enterprise agent tasks, covering areas such as CRM, code, customer service, medical, research and travel.

"Your custom AI agent that can access your confidential data and take consequential action on its own requires a comprehensive and customized approach to quality control," said Vin Sharma, CEO of Vijil.

"There's a big gap between an agent that appears ready in a demo and one that proves its reliability, security, and safety under pressure. DART closes that gap, saving weeks of effort and tens of thousands of dollars compared to manual red-teaming engagements, generic benchmarks, and open source prototypes," he added.

Part of a wider platform

DART is a new capability in Vijil Diamond, one module of the Vijil platform. Once DART has found weaknesses, other modules carry out root-cause analysis, apply policy-driven guardrails and suggest code changes to fix the issues.

Each module can be used separately. Vijil Discover finds and fingerprints agents across an organization, including shadow AI. Vijil Diamond tests agents for flaws before release. Vijil Dome enforces organizational policies in production. Vijil Darwin keeps improving agents as new users, models and attack methods appear.

Our Take

DART is one more sign that security vendors now treat AI agents as their own attack surface rather than as chatbots with extras. The focus on tool use, memory and multi-turn behavior matches the risks that matter once agents can touch real data and systems. It also fits a broader trend of agentic offensive security tools that use AI to attack before criminals do.

For readers running agents in production, the move toward testing inside CI/CD pipelines may be more important than any single feature. It suggests red-teaming could shift from a last-minute check to a routine step, which recent findings on readiness gaps around AI systems indicate is overdue.

The benchmark numbers come from the vendor, so independent testing will be worth watching. It is also worth watching whether adaptive red-teaming becomes a standard expectation for compliance teams.