Major insurers have been retreating from artificial intelligence coverage throughout the past year. Now two founders fresh out of Y Combinator are building their entire company around what everyone else abandoned.
When Fabian Amherd and John Bachmann launched Mount on May 22, they positioned it as something the insurance world hadn't quite seen before: a carrier built exclusively for AI agent liability. Not cyber coverage with a few AI clauses tacked on. Not general liability with careful language around machine learning. A product designed from scratch around what happens when autonomous systems—systems that can send emails, move money, access databases, execute trades—make mistakes.
The timing tells you everything. Since the start of this year, ISO/Verisk's generative AI exclusion endorsements have been in effect across commercial general liability programs nationwide. AIG, Great American, WR Berkley—all began filing for regulatory permission to carve out AI-related claims in July 2025, with exclusions taking effect in January 2026. The message to any company deploying agents with real authority was unambiguous: you're exposed, and we're not covering it.
Amherd and Bachmann looked at that retreat and saw a market.
"Mount is not a generic cyber policy with AI language added on," the company states flatly on its site. "It is insurance built around agent behavior, delegated authority, and measurable workflow loss."
Whether they can actually deliver on that promise—and what their actual regulatory structure looks like—remains an open question.
What They're Actually Selling
The coverage itself targets something specific: direct financial loss stemming from verified AI agent incidents. Four categories. Unauthorized actions. Erroneous actions. Data and tool misuse. Manipulation events like prompt injection or tool injection attacks.
This isn't for companies experimenting with ChatGPT in their marketing copy. Mount is aiming squarely at mid-market and enterprise operations running autonomous agents in production workflows—agents with permissions, system access, and the ability to act without waiting for a human to click "approve."
The underwriting model, according to the company, evaluates deployment environments. What permissions did you grant? Which systems can the agent touch? What controls exist? How bad could it get if something goes sideways?
It's a fundamentally different risk calculus than traditional E&O or cyber policies, which Mount argues were never designed for systems that operate with delegated authority. Whether that differentiation matters to buyers, or whether it's a distinction without a practical difference, will become clearer as enterprises actually start deploying these agents at scale.
If they do.
The Gap That Opened Fast
The coverage void Mount is exploiting didn't appear gradually. It materialized almost overnight.
In November 2025, the Financial Times reported that major insurers were seeking to limit AI exposure, spooked by the specter of multibillion-dollar liability claims they couldn't model. Mosaic Insurance called large language models a "black box" that posed systemic risk—the kind of language that makes underwriters reach for exclusion forms.
By January, those worries had hardened into formal policy language. Verisk's standardized exclusion forms, filed the previous July with a New Year's effective date, gave carriers a uniform way to wall off AI-generated injuries. S&P Global Market Intelligence noted in February that the exodus was accelerating, leaving deployers scrambling to quantify exposures their policies no longer covered.
Mount's blog post from April 13 doesn't mince words: "Most policies have AI exclusions or ambiguous language" that leaves companies holding the bag when agents malfunction.
The question is how many companies are actually deploying agents risky enough to need dedicated coverage—and how many are willing to pay for it.
The Workflow Strategy

Mount plans to offer insurance bundled with security testing, a combination that reflects Amherd's background in computer science and machine learning at ETH Zurich.
The workflow runs in three steps: scan and red-team the deployment to surface vulnerabilities, quantify and secure those risks, then insure whatever residual exposure remains. It's a consulting-plus-coverage model that could appeal to enterprises navigating unfamiliar territory—or feel like overkill for companies that haven't experienced an agent-related loss yet.
The company is also developing something it calls "ADR certification," positioning it as the AI agent equivalent of SOC 2. Whether that credential gains any market traction remains entirely speculative—no third-party adoption has surfaced publicly. But the ambition is clear: Mount wants to set industry standards, not just collect premiums.
When the product launched, Sam Altman's endorsement appeared prominently on the YC Launches page: "I think this is a great idea... Insurance is shockingly important to how society works. No one is doing a good job of underwriting this right now."
That's useful marketing. It's not a customer.
A Startup Claiming to Be a Carrier
Here's where things get fuzzy.
Mount is a two-person operation. Amherd handles product and the underwriting model. Bachmann, who previously founded an AI-first media company, runs operations and growth. They closed Y Combinator's standard funding in March as part of the Spring 2026 batch and are actively hiring for go-to-market, AI engineering, and underwriting roles.
What Mount hasn't disclosed publicly—and what matters enormously—is its actual carrier status.
The company describes itself as "building the AI-Agent insurance carrier." Fine. But no regulatory filings, fronting carrier partnerships, or reinsurance arrangements have surfaced in public records. Mount markets itself as building an insurance carrier, but lacks public regulatory filings for verification. You can't just declare yourself a carrier and start collecting premiums. State insurance departments have opinions about that sort of thing.
The gap between positioning as a carrier and holding admitted or surplus lines authority is measured in quarters, if not years. It typically requires substantial capital, regulatory navigation across multiple jurisdictions, and either building balance sheet capacity from scratch or partnering with an established fronting carrier willing to put its paper at risk.
Which structure Mount is pursuing—or whether it's operating in some gray area pending approvals—the company hasn't said. That will need resolution as it scales, assuming it does.
A Crowded Nascent Category

Mount isn't the only player chasing AI liability, though it may be the most narrowly focused.
HSB, a Munich Re subsidiary, launched AI liability insurance for small businesses on March 18, covering bodily injury, property damage, and advertising injury from AI-generated content. Corgi, another YC-affiliated company that secured carrier approval earlier this year, includes AI liability in its startup coverage bundle. Lloyd's-backed players—Armilla, partnered with Chaucer, launched in April 2025, and Testudo, which went live in January—offer affirmative AI liability through specialty programs.
The difference, Mount would argue, is focus.
HSB targets SMBs worried about content liability. Mount is zeroing in on workflow risk—the financial loss when an agent with system access and delegated authority does something expensive or dangerous. That specificity could be a competitive advantage, or it could paint the company into a corner, depending on how quickly enterprises deploy genuinely high-stakes agents and how messy the loss patterns turn out to be.
The early data doesn't exist yet. No one knows what AI agent claims actually look like at scale, because the deployments generating those claims are still mostly theoretical.
Regulatory Winds (Maybe)
The timing might work in Mount's favor, at least on paper.
The EU AI Act's high-risk AI system obligations are phasing in around August 2, and Colorado's AI Act takes effect June 30. Both laws impose documentation and risk management requirements on deployers, creating what could be a compliance wedge for third-party certifications and insurance products.
According to Mount, companies have a narrow window—six to twelve months, perhaps—to secure coverage before the category hardens or pricing spikes. Whether that urgency resonates depends entirely on how many production agent deployments actually materialize, and how many of those generate insurable losses that make headlines.
So far, the theoretical risk outpaces the demonstrated losses by a wide margin.
What's Missing

Mount has no public customer logos. No case studies. No disclosed claims experience.
It has a product page, a blog, and a YC launch post.
For a company positioning itself as a carrier, the absence of public policy forms, limit structures, or pricing methodology is notable. So is the lack of clarity around regulatory infrastructure—state approvals, surplus lines eligibility, backing capacity.
These aren't necessarily red flags for a company that launched just days ago. But they're the first questions enterprise buyers and risk managers will ask before signing anything. Insurance is a regulated, capital-intensive business built on demonstrated capacity and legal authority to bear risk. Branding and positioning only get you so far.
The product is live. The team is hiring. The market gap is real, or real enough.
What remains to be seen is whether Mount can move fast enough to define the category before larger players with established balance sheets, regulatory infrastructure, and distribution networks decide AI agent risk is worth underwriting after all. Or whether the agents everyone's worried about remain vaporware long enough that the urgency evaporates.
In insurance, gaps close fast when there's money to be made. And they close faster when the risk turns out to be manageable.
That's the bet Mount is making.
