From Behavior to Breach: Linking Assessments to Legal Obligations
The link between a behavioral measurement layer and an agent-native obligation graph

PAICE (People + AI Collaboration Effectiveness) measures how a licensed professional behaves when they work with AI on a real task. The measurement is behavioral. It is not a knowledge test about AI, not a survey of attitudes, and not a recording of how fluent the person sounds. The questions PAICE answers are operational: did the professional catch the injected error, did they exercise independent judgment when the model was wrong, did they recover when the workflow broke.
ObligationFirst announced last month represents legal obligations in a structured form agents can reason about. Actor, action, condition, deadline, authority, exception.
These two layers do something interesting when they meet. They let us say, for a specific behavior in a specific assessment, which obligation under which statute that behavior implicates. Not at the level of "this profession is regulated, therefore AI use is risky." At the level of "in this turn of this assessment, the professional took an action that would have breached a named duty under a named law."
That is a different and stronger claim than what AI assessment tools currently make. This post shows the mechanic, end to end.
PAICE.work PBC is not a law firm and does not provide legal advice, opinions, or recommendations. The services provided are for informational or administrative purposes only.
The Two Layers, Restated
PAICE measures behavior across five dimensions: Performance, Accountability, Integrity, Collaboration, and Evolution. Each dimension is operationalized as observable conduct during an assessment, not as a self-reported attitude. The scoring is intentionally conservative: absence of evidence is low score, not benefit of the doubt. The architectural premise is that conversation is the medium, not the measurement. What gets scored is what happens, not what the person says about what happens.
ObligationFirst represents the legal obligations a regulated actor must meet. Each obligation has a structured record with stable identifiers, supersession relations, authority chains, and provenance pointers back to PubLedge artifacts. The schema is agent-native, designed for query and execution rather than human browsing.
Both layers exist independently. PAICE works without ObligationFirst — it tells a professional, and their employer's training function, how that professional collaborates with AI on the dimensions that matter. ObligationFirst works without PAICE — it tells a compliance tool which duties apply to which actor under which conditions. The link between them is what is new.
A Worked Example
Consider a Utah-licensed contract attorney using a generative AI tool to draft a clause in a commercial agreement. The attorney is taking the PAICE assessment for the legal vertical. Inside the assessment, the AI tool generates a clause that contains a subtle but material error: a cure-period provision references a statute that was repealed two years ago and replaced by a successor statute with different timing.
Three things can happen in the next turn.
The attorney can notice the citation, recognize that the cited statute was repealed, and correct or replace it. PAICE records this as a catch on the Integrity dimension and a strong signal on Performance — the professional did the verification step that the situation demanded.
The attorney can not notice, accept the clause as drafted, and use it. PAICE records the miss. The score reflects the failure to verify a cited authority on a material term.
The attorney can notice, hesitate, ask a clarifying question of the AI, get a confidently wrong answer, and proceed anyway. PAICE records the partial catch with subsequent overcorrection — a known failure pattern.
In all three cases, PAICE produces a behavioral score that tells the professional and their employer how they collaborated with AI in that moment. That is what PAICE does today.
Now add the obligation layer.
What the Obligation Layer Adds
The behavior in the second case — accepting an AI-generated clause containing a repealed statute citation, on a material term, without verification — is not just a low Integrity score. It is, in Utah, an action that touches several named obligations.
It touches the attorney's duty of competence under the Utah Rules of Professional Conduct Rule 1.1, which requires the legal knowledge and skill reasonably necessary to the representation, including the duty to keep abreast of relevant technology. It touches the duty of supervision under Rule 5.3 to the extent the AI tool is treated as a nonlawyer assistant. Depending on facts, it may touch disclosure duties to the client under Rule 1.4. And if the AI use is in a consumer-facing legal context, it may touch Utah SB 149's disclosure obligations.
Each of those duties has a structured record in ObligationFirst. Each record names the actor (licensed attorney in Utah), the action (verify cited authority, supervise AI output, disclose AI use), the condition (use of generative AI in client work), the authority chain (state bar rules, SB 149, Utah Office of AI Policy guidance), and the exceptions (none particularly relevant here).
The link is a mapping between the behavior PAICE observes and the obligation record the behavior implicates. The mapping is not a verdict. It does not say the attorney breached a duty in court. It says: this behavior, performed in this context, by an actor in this role, is the kind of behavior that a regulator or litigant would assess against this named duty. The link is precise about which duty.
Why Precision Matters Here
Regulated industries have heard the broad version of this claim for years. "AI in legal work is risky." "AI in healthcare requires care." "Your team needs training." Those statements are true and useless. The action they imply is open-ended. The accountability they create is diffuse.
A precise mapping from behavior to obligation changes the operational picture. A managing partner reviewing a firm-wide PAICE cohort report cannot see any individual score — that is structural, the privacy architecture forbids it — but they can see, at the cohort level, that a measurable fraction of behavior is implicating Rule 1.1 verification duties. That is an actionable signal. It points to training that addresses the specific behavior pattern.
A regulator, presented with an enforcement action, can ask whether the firm had a measurement program in place that would have caught the behavior at issue. The presence of PAICE plus ObligationFirst in a firm's AI governance posture is not a defense. It is a documented fact about whether the firm could have known. Documented facts are the currency of regulated industries.
A litigant, building a case, can match the alleged breach against the obligation graph and the firm's behavioral evidence in a way that survives cross-examination. The mapping is structured, not narrative. That changes how the dispute proceeds.
Why No One Else Can Make This Link
The mapping requires both layers, and neither is trivial.
A behavioral measurement layer that means something requires a deliberate scoring architecture that treats observation as primary and fluency as secondary. Most AI assessment tools on the market score what the person says they would do, not what they did. PAICE is built around the opposite premise. Tests over conversation, always. The architecture is the moat.
An agent-native obligation graph requires a representation that an agent can query and reason against. Prior machine-readable-law efforts have produced excellent representations for human-operated software. The agent-native framing is what ObligationFirst contributes.
Holding both layers, and connecting them with stable identifiers, is not a feature that competitors can ship in a quarter. It is structural. It is also why this work has taken the shape of a portfolio rather than a product.
What Is Live Today and What Is Roadmap
The behavioral measurement layer is live. PAICE assessments run today against the five dimensions, with conservative scoring, privacy-by-architecture cohort reporting, and tier thresholds calibrated against regulated-industry stakes.
The obligation graph is live in beta. ObligationFirst is published. The Colorado AI Act worked example was also published last month. Utah SB 149 is modeled. Other jurisdictions are in queue.
The explicit link between the two layers — assessment results that surface mapped obligations — is the next product surface. The mapping logic and the obligation identifiers are in place. The user-facing reporting that surfaces "this behavior implicates duty X under statute Y" is in design. Watch for it.
What This Means for the Reader
If you are a regulated professional, this is the shape of what PAICE will tell you about your own AI collaboration. Not just how you scored on Integrity. Which duties were in play when you did or did not catch the error.
If you are running an AI governance program inside a regulated firm, this is the shape of the operational evidence you will be able to put in front of regulators, auditors, and your own board. Structured. Specific. Defensible.
If you are building compliance tooling for regulated industries, the mapping layer is public. You can build against it without us.
The behavior and the law are now in the same graph. The link is what makes the rest tractable.
Want to assess your team's AI collaboration readiness? Learn about PAICE for organizations or take an individual assessment to see it firsthand.
Curious but short on time?
Take the 3-minute PAICE Pulse — a quick confidence check that maps how you see your own AI collaboration posture. No login required.