RiskMandate v1.4.0
Startup Summit · 17–18 September 2026 · Lisbon

Do you know what your AI agent can actually do?

Most teams can't answer it. We will be at Startup Summit in Lisbon for two days, and the whole of our stand is built around answering it for one agent you already run — in about five minutes, on paper, with nothing connected to anything.

The document behind it →
The event

Startup Summit, Lisbon.

Two days at the Unicorn Factory Lisboa, in the Beato Innovation District. We are exhibiting, on a one-metre startup booth. If you are going and want a slot rather than a queue, say so and we will hold one.

Dates17–18 Sept 2026Thursday and Friday
VenueUnicorn Factory LisboaBeato Innovation District, Lisbon
UsExhibitingstartup booth · number assigned nearer the date
Organiser's figures2,000+ founders300+ investors · 150+ speakers · 200+ stands · 3 stages · 40+ countries
Not affiliated. RiskMandate is an exhibitor. This page is ours, not the organiser's — we are not affiliated with or endorsed by Startup Summit, and nothing here is an official event communication. Attendance figures above are the organiser's own, published on startupsummit.io; for the agenda, tickets and anything about the event itself, go there.
At the stand

Four things, in this order.

Everything below already exists and is public. You can run all of it before you arrive, on your own machine, without talking to us — which is rather the point.

  1. 01

    A draft Agent Behaviour Policy, on paper, for an agent you run

    Tell us which agent and roughly where it runs. We hand you a printed draft: everything it can do, what we think you authorised, the gap, and what is actually standing in the way. Then you correct it — and the correction is usually upward, which is the finding. Nothing is sent anywhere and we need no access to anything of yours, because a draft is about a deployment shape rather than about your estate.

  2. 02

    The permission game — five minutes, forty questions, no sign-up

    Guess what an agent can reach, then find out, then get scored on how well you knew. It runs on the screen facing the aisle all day and needs nobody to operate it. Play it now if you like; it is the fastest way to understand what we do.

  3. 03

    Licence to Operate — an insurance policy for an agent, simulated

    The grant, the mandate, and the delta that nothing covers. It is the argument made operable: the prohibitions an agent needs are the exclusions an insurer would write, and an underwriter cannot exclude what nobody enumerated.

  4. 04

    The Insurability Index — the number, and where it is allowed to live

    A score over five weighted dimensions, derived from your environment rather than a self-assessment, with six levels from Unmapped to Underwritten. It scores the deployment. It never scores the behaviour policy, because the same policy is dangerous in one deployment and harmless in another.

Who this is for

Four conversations. One ask each.

Find whichever of these is you. We would rather have the right five-minute conversation than the wrong twenty-minute one.

You run agents today

You gave an assistant access to a repo, a mailbox, a cloud account

“Do you know what it can actually do? Not what it did — what it can.”

You almost certainly know what you asked for. Nobody enumerates the rest. Your first serious enterprise customer will send a security questionnaire with agent questions on it, and your insurer and any acquirer will ask the same thing.

The ask: a draft, corrected, as a file you keep — £10

You back companies that do

Agent exposure is sitting un-priced across your whole book

“How many of your portfolio companies could tell you what their agents can reach?”

None of them has written it down, and none of your diligence asks. We make it a per-company document and a portfolio view. There is no productised, affordable review of this at any price today.

The ask: a person reading three companies with you

You are a founder raising

You will be diligenced on this before long

“Would you like to know what diligence will find, before it runs?”

The usual version of this — buy a posture document — is already free in several places, so we are not selling you that. The useful direction is the opposite one: the finding before somebody else makes it.

The ask: the reverse review — come and ask

You sell a control

We can count what your product actually takes away

“Would you like a number for how much of an agent's reach your product removes?”

Only one of the four barrier kinds bounds anything: a boundary enforced above the grant, out of the agent's reach. Your product moves capabilities into that row; we count them, for named deployment shapes, from published data, with no verdict attached.

The ask: a partner conversation, not a transaction

One ask per conversation, never two. If none of the four is you, take a card — we would rather be useful later than wrong now.

Press and media

Boilerplate, ready to paste.

Copy any of this without asking. If you need something that is not here — a quote on the record, a figure, a founder bio, a briefing at the event — use the button in the header and say what you are writing and by when.

One line37 characters

The insurability layer for AI agents.

Short — about 50 wordsfor a listing or a caption

RiskMandate makes autonomous systems insurable. We map every agent to what it can actually reach, assign a named owner, and turn an open-ended grant into a time-boxed acceptance a board can carry. The output is an Insurability Index — a number your customers, insurers and investors can ask for.

Long — about 170 wordsfor a profile or a preview piece

An AI agent's grant is not its mandate. The moment an agent runs it holds authority nobody scoped and nobody time-boxed — and that risk is already accepted, whether or not anyone signed for it.

RiskMandate makes that explicit. It starts with an Agent Behaviour Policy: a written description, for one agent in one deployment, of everything it can do, what it was authorised to do, the gap between the two, and what actually stands in the way. The policy describes and does not judge, so it carries no score. Above it, RiskMandate models the environment the agent is really in, and converts the standing grant into an acceptance with a named owner, a direction and an expiry — underwritten upward to the board. There is no deny button: a live risk cannot be refused, only accepted for an interval.

The result is an Insurability Index: a computed score against a real conformance standard rather than a self-assessment. Built on zero-knowledge encrypted vaults — the register stays with the customer, and can be handed to an auditor with a single read key.

Facts a writer usually needsall checkable on this site

Name: RiskMandate — one word, two capitals. Not “Risk Mandate”, not “RISKMANDATE”.
Site: riskmandate.ai · Category: AI governance, risk management, cybersecurity
What is public today: six live demos, each opening its own encrypted vault with a deliberately published read-only key; the Agent Behaviour Policy model and its data as JSON at stable addresses; and this site's full version record.
Built on: SG/Vault — zero-knowledge, PKI-backed, no database.

AccurateNot accurate — please don't
“measures insurability and produces the evidence underwriters price against”that we are an insurer, a broker or an MGA, or that we sell or place cover
“the behaviour policy carries no score”any rating, traffic light or risk level attached to a behaviour policy
“a computed score against a conformance standard”that anything here is a compliance assessment, a certification or a conformity mark
“read-only, and never in the request path”that RiskMandate blocks, gates or enforces anything
“complementary to GRC, identity and posture tooling”that it replaces any of them

These are the same rules our own pages follow. The reason for each is written down: no claim goes on this site that is not defensible, and nothing here carries a verdict about a named third party.

Materials

Take what you need.

The mark, the lockups and the machine-readable versions of everything on this site. No form, no email, no attribution required beyond not implying we endorsed your piece.

The mark is a seal — a stamp with a monogram inside it, registration ticks on the axes, a quiet inner ring. It is ink #161615 and green #1A7F5A, never another hue, never stretched, and never below 24px in its detailed cut. The five things not to do.

Afterwards

You get a working artefact, not a deck.

  • Within 48 hours of the event, everyone who bought a draft gets their corrected behaviour policy as a file they keep — not a PDF of a slide, a document with its inputs and its dates in it.
  • Everything we show is already public, so nothing you see at the stand depends on us following up. The demos, the model and the data are linked from this page.
  • If you would rather not queue, use the button in the header and name a time on the 17th or 18th.
17–18 September · Unicorn Factory Lisboa

Bring one agent you already run.

That is all we need. Not credentials, not access, not a diagram of your estate — just which agent, and roughly where it runs. Five minutes later you will know something about it that you did not know when you walked up.

})();