The autonomous agent has slipped into corporate infrastructure faster than anyone quite expected. Somewhere between the AI hype cycle and actual enterprise deployment, a new operational reality took hold: software systems now initiate wire transfers, access customer databases, and execute business logic without waiting for human approval. Which raises a practical question that sounds almost quaint in its directness—when the agent screws up, who covers the loss?
Mount, a startup that emerged from Y Combinator's Spring 2026 cohort, is wagering it can answer that question before the market figures out how to ask it properly. The San Francisco company launched publicly in mid-April with an offering that tries to do something ambitious, perhaps improbably so: collapse security testing, risk certification, and actual insurance underwriting into a single platform for companies running AI agents with what Mount calls "real permissions, tools, and operational authority."
It's a bet on infrastructure—the kind that only makes sense if you believe the agent economy is genuine and arriving fast.
The Coverage Layer Nobody Asked For (Until Now)
Mount's insurance product targets the financial fallout from verified AI agent incidents. The mechanics, at least as described on the company's website, split into two buckets. First-party costs include data restoration and model retraining, business interruption when an agent-driven failure cascades, incident response and regulatory bills, API cost overruns during security events, and—perhaps the most visceral exposure—incorrect funds transfers triggered by agent errors.
Third-party exposures cover the messier terrain: harmful or infringing outputs the agent generates, privacy breaches, service failure claims from downstream customers. These aren't theoretical risks borrowed from traditional cyber policies. Mount frames them as native to systems that operate autonomously, making decisions in real time without a human gate.
The attack surface it's underwriting includes the now-familiar litany of vulnerabilities catalogued in OWASP's 2026 Top 10 for Agentic Applications: prompt injection, tool injection, unauthorized actions, data misuse, manipulation events. Mount says it writes coverage based on how the agent actually behaves in production—its capabilities, the access it holds, its control architecture, the exposure profile of the live environment.
What the company doesn't say, at least publicly: how much coverage it writes, at what price, through which carrier. Policy limits, deductibles, jurisdictions—all undisclosed as of mid-May. The website offers quote requests and a free agent security test via calendar links, but nothing resembling a specimen policy or rate card.
More Than Just a Policy

Mount positions the insurance as one component of a broader workflow, which is where the pitch gets more interesting or more complicated, depending on your tolerance for startups trying to do multiple things at once.
The platform runs continuous vulnerability scans and risk scoring on deployed agents, surfacing findings for remediation alongside a numeric risk assessment. That data feeds Mount's underwriting engine—proprietary risk intelligence that the company says lets it price agent-specific exposures rather than shoehorning them into existing cyber or errors-and-omissions categories.
There's also an "Agent Deployment Readiness certificate" in the works, described on the homepage as coming soon. Think of it as a buyer-visible credential for AI vendors—the framing on Mount's Y Combinator profile calls it "SOC 2 for AI agents." The certificate would formalize the security and control posture that determines insurability, giving vendors a way to signal reduced risk to enterprise procurement teams who increasingly care about such things.
The founding team is compact. Fabian Amherd, who studied computer science at ETH Zurich and previously worked on real-time object detection at MESH, a robotics spinoff, leads product and AI risk evaluation. Co-founder John Bachmann, formerly the founder of Horizonn (an AI-first media company in Switzerland), handles operations and growth. Mount lists two open roles on its YC profile: a go-to-market position ($50k-$120k) and a founding AI engineer focused on underwriting and AI risk ($170k-$210k), with equity ranging from 0.40% to 1.40%. Standard early-stage staffing, in other words.
A Suddenly Crowded Niche

Mount launched into what had been a quiet corner of the insurance market—until it suddenly wasn't. The timing is striking, if not entirely coincidental.
On February 12, AIUC announced AI agent insurance in partnership with ElevenLabs, built around its AIUC-1 certification standard. Corgi launched purpose-built AI insurance coverage on May 4, addressing biased algorithms, harmful generated content, training data misuse, adversarial attacks, and autonomous system failures. European entrant Agent Insured pitches ISO/IEC 42001 alignment and coverage across overlapping EU liability regimes. Klaimee and Keel offer variations on risk rating and certification, though Klaimee notes its insurance component remains under development.
The April-May window also brought a wave of infrastructure announcements from the insurance industry itself. Duck Creek launched an agentic AI platform for underwriting and claims on April 28. Vertafore introduced its Velocity AI platform with agent capabilities two weeks earlier. Verisk announced Claude connectors for insurance analytics on May 5, and Roadzen followed two days later with AI agents on Anthropic's managed platform. The rapid succession suggests carriers and core-system vendors are building out agent workflows internally, creating the operational substrate that makes agent-liability insurance relevant rather than hypothetical.
Mount's April 13 blog posts frame the category's timing as analogous to cyber insurance's emergence decades earlier. One post claims "the first AI agent insurance policy was underwritten in early 2026," situating Mount's launch not as a greenfield invention but as an entry point into a forming market. Another unpacks liability under the EU AI Act and various U.S. sector regulators, sketching the compliance backdrop that makes coverage necessary for companies operating across jurisdictions.
The Details That Aren't There Yet

What Mount hasn't disclosed might matter more than what it has. No carrier or reinsurer partners are named. Policy structure, admitted versus non-admitted status, regulatory posture—whether it operates as a managing general agent, broker, or surplus lines entity—all remain undefined. Its Y Combinator funding, a standard $125,000 check in March 2026 according to Dealroom, is the only public capital figure. No customer names, no case studies, though the homepage references "securing AI by the world's top providers," a claim that's difficult to verify.
The product appears functional—quotes and testing are available via the website—but the absence of granular terms, limits, and pricing makes it hard to assess whether Mount is writing significant volume or still proving out the model at small scale. The company's Spring 2026 YC batch would have held its demo day in late March or early April. No subsequent funding announcements have surfaced since.
What seems less debatable is the problem Mount is trying to solve. Autonomous agents are moving from pilot projects to production systems. The OWASP framework, EU regulatory obligations, and carrier infrastructure investments all point toward standardized risk management becoming a requirement rather than a nice-to-have. Whether Mount's integrated model—security, certification, and insurance bundled together—becomes the default architecture or simply one approach among many will come down to execution details the company hasn't yet made public.
For now, it's a startup with a provocative thesis: that the machines moving money and making decisions need their own form of accountability, and that accountability needs to be underwritten. Perhaps the more interesting question isn't whether Mount succeeds, but whether the fact that multiple companies are now racing to insure AI agents tells us something about how quickly those agents have become critical infrastructure.
