There's a moment in every new technology cycle when the old guard decides they've seen enough. For artificial intelligence, that moment appears to have arrived in early 2026—or at least, that's when major cyber insurers began excluding AI-related claims from their policies. Left in the lurch: companies deploying autonomous agents that can book flights, process refunds, or modify code without human supervision.
Mount, a San Francisco startup that emerged from Y Combinator, thinks that gap is large enough to build a business around. Perhaps more than that—the company is positioning itself in what it sees as an entirely new insurance category, one where underwriting begins not with paperwork but with actively trying to break the thing you're about to insure.
"The AI Agent Insurance Carrier." That's how Mount describes itself, a positioning that co-founder John Bachmann frames in explicit contrast to what he dismisses as the legacy approach: "generic cyber with AI language." The company went live in April 2026 with AI Agent Liability Insurance, aimed squarely at mid-market and enterprise customers running autonomous agents in production. These are deployments where an agent's access to customer databases, payment rails, or operational levers creates a kind of downside that simply didn't exist when software followed more predictable paths.
Red-Teaming Before Underwriting
Mount's product model breaks from convention. Rather than issue a policy based on questionnaires about governance frameworks, the company scans and red-teams the AI deployment first. The goal is to surface vulnerabilities—what the agent can actually do, what it accesses, what it controls—then help the customer fix those gaps before insuring what remains.
The policy covers four flavors of agent misbehavior: unauthorized actions, erroneous actions, data or tool misuse, and what Mount calls manipulation events—think prompt injection or tool hijacking that results in harmful output. The company frames these as operational risks specific to agent autonomy, distinct from traditional cyber exposures like data breach or business interruption.
What Mount hasn't disclosed: pricing, policy limits, or the reinsurance arrangements that would give the coverage teeth. Those details matter, especially for a startup positioning itself as a carrier rather than a distributor.
A Technologist and an Insurance Lifer Walk Into YC

Fabian Amherd studied computer science and machine learning at ETH Zürich and previously ran a web development company. John Bachmann comes from a multi-generation insurance family and most recently founded an AI-first media venture. One founder who can reverse-engineer how an LLM fails, one who understands how carriers price tail risk. The pairing mirrors the product's dual nature—part security assessment, part financial instrument.
Y Combinator listed the team at two during the Spring 2026 batch, though the company has likely grown since launch. What emerges from the launch narrative is a conviction that AI agent insurance occupies roughly the same structural position cyber insurance held two decades ago: a risk everyone acknowledges, few policies genuinely cover, and a product category ripe for professionalization.
Bachmann and Amherd may be right. Or they may be early. The market is still figuring out what "agent liability" even means.
The Exclusion Wave and the Gold Rush That Followed

Mount didn't create the opportunity so much as walk through a door that incumbent carriers opened. The ISO and Verisk exclusions that took effect in early 2026—specifically CG 40 47, CG 40 48, and CG 35 08—effectively carved generative AI exposures out of standard commercial general liability and cyber policies. Demand for affirmative coverage materialized quickly, and new products followed.
HSB introduced AI liability insurance for small and mid-sized businesses in March. CFC embedded affirmative AI coverage across tech errors and omissions, professional indemnity, and cyber portfolios by June, addressing risks like hallucination and model drift. Mayflower Specialty and Hadron launched what they termed the "first dedicated affirmative AI liability program" in the U.S. on June 24, targeting management liability—directors and officers, E&O, employment practices. Testudo, working with Lloyd's capacity, began underwriting generative AI liability for the U.S. mid-market early in the year. Armilla, which launched affirmative AI liability with Lloyd's underwriter Chaucer in 2025, raised its capacity to $25 million in January.
ElevenLabs announced what it called "first-of-its-kind AI agent insurance" in February, linked to a certification standard, though carrier and reinsurer details remained murky. Mount's own blog suggests "the first AI agent insurance policy was underwritten in early 2026," predating the company's April launch. What Mount claims as distinctive is narrower: a carrier model purpose-built for agentic action risk, not a generative-AI rider grafted onto existing products.
The "first" claims are proliferating faster than anyone can verify them. Category definitions remain fluid. Is agent liability a subset of AI liability, or a fundamentally different animal? The market hasn't settled the question.
The Regulatory Silence
Here's what's conspicuously absent from Mount's website: licensing disclosures, admitted or non-admitted status, NAIC identifiers—the regulatory markers typical of an entity binding insurance policies. It's unclear whether Mount is writing coverage on its own paper, operating through a fronting arrangement, or functioning as a managing general agent with carrier partners in the background.
That ambiguity isn't unusual at launch. Many insurtechs announce products before their regulatory infrastructure becomes fully visible. But it matters—particularly for customers trying to evaluate whether the coverage will actually perform when a claim arrives and lawyers start parsing language.
The competitive framing gets similarly murky under scrutiny. Several players have claimed some version of "first" in AI liability, and the category boundaries shift depending on who's defining them. What's clearer from trade press coverage and executive interviews is a broader pattern: specialized MGAs and carriers writing affirmative AI cover while traditional carriers retreat behind exclusions. It's a dynamic that echoes cyber's early years, when established players decided the risk was unquantifiable and startups rushed in.
Runtime Underwriting as Competitive Edge—Or Guess

Mount's differentiation appears to rest on what it calls runtime underwriting: using red-teaming and risk scoring to understand what an agent can do in practice, rather than relying on attestations about policies and procedures. If that approach proves sustainable—if it correlates with actual loss experience—it could define the underwriting standard for agentic systems going forward.
If it doesn't, Mount becomes another insurer making educated guesses about tail risk with insufficient historical data.
For now, the product exists. The messaging is sharp. The market tailwind from exclusions and rising deployment is real. Whether Mount becomes the category winner or an instructive early experiment depends on execution details the company hasn't yet disclosed: claims-paying capacity, loss ratios, the sophistication of its red-teaming, the willingness of reinsurers to back the risk as agent deployments scale.
The old cyber insurers decided they'd seen enough and walked away. Someone had to walk in. Mount is betting it can be more than just the first through the door.
