Weekly Update - June 29, 2026

End of Q2 — security hardened, open-weight scoring ships soon, and a quarter worth naming.

by Sam Rogers
11 min read
update
technical
security
quarterly
implementation
open-weight
Weekly Update - June 29, 2026

As Q2 ends tomorrow, this is our weekly review and our quarterly review in one.

This week was a hardening week: the platform's security policy was tightened across the board. The open-weight scoring transition is close behind it — no outside provider in the path between a professional's assessment and their score. Five posts shipped as usual, closing the week with a buyer-facing content arc — business case, cost of failure, audit trail design — and a video on individual licensee accountability. Because it's the last update of the quarter, this one includes a full Q2 retrospective — the platform moved onto infrastructure we control, the purchase-to-access path went live, seven new PAICE Portfolio sites launched, and the evidence layer got its scoring foundation.

Content Published Last Week

Monday (June 22): "Weekly Update - June 22, 2026"

Tuesday (June 23): "Building the Business Case for AI Collaboration Assessment" A practical framework for enterprise buyers building internal support for behavioral assessment. The CFO asks "what's the ROI?" The CISO asks "what's the risk of NOT doing this?" This post gives the buyer the answer to both questions before the procurement conversation starts.

Wednesday (June 24): "The Cost of Getting It Wrong" The other side of the ROI ledger. Most organizations can estimate what AI saves them. Almost none can put a number on what one unverified output costs when it reaches a client, a patient, or a regulator. This post fills in that blank for regulated industries — malpractice exposure, regulatory fines, license risk.

Thursday (June 25): "Audit Trails for AI-Assisted Decisions" When a regulator asks how a decision was made, the finished report is not the answer. The process is — and most organizations cannot reconstruct it. A practical framework for documenting AI-assisted decisions so the answer exists before the question is asked.

Friday (June 26): Video - "The Accountability Gap" 6min video. Three letters arrive from three regulators in three different professions. Each names a single human being. Not the firm, not the AI vendor, not the committee that approved the tool. The accountability chain does not break — it terminates exactly where the regulators designed it to terminate, on one person with a license.

Open-Weight Scoring Ships Soon

Here's a preview of a big announcement on the way: PAICE assessments will score entirely on open-weight models. The last dependency on an outside provider in the scoring path is being replaced. No outside provider will sit between a professional taking the assessment and the score they receive.

This is the completion of work that has been building all quarter. The scoring benchmark — rebuilt from the ground up, with a head-to-head bake-off of open-weight candidates, hundreds of scoring runs, and a scoring defect caught that live operation hadn't surfaced — is producing the evidence the final call will rest on. The transition matters for three reasons:

Privacy. Open-weight means the models are public, inspectable, and reproducible. Assessment data never leaves infrastructure we control. Nothing carries professional behavioral data to an external provider.

Reproducibility. Outside providers change their models without notice. Open-weight models are pinned. The same input produces the same output. That matters when scores inform compliance, professional development, or organizational governance decisions.

Independence. PAICE's scoring no longer depends on a vendor's pricing, availability, or policy decisions.

The assessment methodology, the five dimensions, the scoring rubric, and the 0–1000 scale are unchanged. This is a foundational transition, not a methodology change. The full announcement is coming soon.

Security Hardening

The platform's security policy was tightened across the board this week, closing off the most common avenue an attacker uses to inject code into a page and adding automated checks so the policy can't quietly regress. Unused data left over from an earlier feature was cleaned out at the same time.

Platform Stability

All three environments (production, staging, pilot) operating normally. Zero unplanned incidents. Automated daily health checks and weekly backup restoration drills continue running without issue.


Q2 2026 Quarterly Retrospective

Q2 ran from April 1 through June 30. Here is what shipped.

Product and Revenue

PAICE Pro Packs launched: 5-pack and 10-pack bulk purchases of the PAICE Pro product that bridges between single users and Enterprise users. Full pricing published openly with every tier on the page, no sales gate. To make that sale actually work, the whole purchase-to-access path shipped this quarter: sign-in, payment, and team activation, so a buyer can pay and a team can get started without a human in the loop.

Pulse shipped as a named product — the 3-minute confidence check at /pulse, the low-friction front door to the full assessment.

The papers library launched with six papers under /papers in a browsable, citable, in-browser reader. The five-part dimensions series completed. Positioning sharpened to its clearest formulation: PAICE is the evidence layer for AI governance.

Infrastructure

The biggest engineering story of the quarter does not appear in any product demo: PAICE moved its entire platform onto infrastructure we control directly and stood up three real environments. Production, staging, and pilot now run as fully isolated environments with isolated data. Automated nightly backups now run with a 30-day retention window. Outbound email moved to a dedicated delivery service. There is no longer any third party in the critical path between PAICE and the professionals it serves.

Reliability and observability hardened alongside the move: durable error reporting, session-level diagnostics, automatic recovery when a page is left stale by a mid-session update, and improved search-engine discoverability.

PAICE Portfolio

The PAICE Portfolio went from a handful of projects to a federation. Each of these projects was started because we needed it for PAICE.work to meet specific business targets. Seven new sites launched on paice.foundation this quarter:

  • AI Posture (April) — a framework for declaring and assessing an organization's AI posture, the umbrella the dimensions and whitepapers now sit under.
  • Siteline opened for business (April) — scores any public site for AI-agent usability on the SNAP rubric.
  • ObligationFirst launched with the Colorado AI Act as its pressure-test worked example. This is what makes law machine-readable, and is now the underlying foundation for EveryAILaw.com (launched in Q1) and the rest of the PAICE Legal Graph. This is also the analysis method that allowed PAICE.work PBC to submit formal comments on the EU's draft Article 50 transparency guidelines, our first direct engagement with a regulatory process.
  • EveryAILaw Pro (April) — the paid tier of the regulation catalog, bringing our internal MCP usage to a wider audience.
  • AI Incident Law (April) — a dataset and reference site built for our whitepaper library but useful to others tracking AI risk.
  • PubLedge (April) — a public-ledger pattern for verifiable publication records, developed for our outreach to state agencies regulating AI.
  • GuideCheck (May) — conformance checking of AI-install guidance against a declared standard. Mitigates prompt-injection risk for specific use cases.
  • Tokenese (June) — an open spec for a token-native interlingua for LLM-to-LLM communication. Still in R&D mode, but actively being built withing our Turnfile framework we launched in Q1.

Multilingual

The i18n work that began with Urdu in March reached full-site coverage by mid-June: every public-facing page in Latin American Spanish, French, and Brazilian Portuguese. 809 UI strings per locale, ~150 blog posts translated, three languages graduated from beta to fully supported. Though we pulled back on our target of delivering more European languages when the EU AI Act enforcement dates shifted, we're still committed to adding more languages in the future.

Scoring Bench

The scoring benchmark was rebuilt from the ground up. A head-to-head bake-off pitted the existing scoring model against a field of open-weight candidates across hundreds of scoring runs. The benchmark caught a scoring defect that three months of live operation hadn't surfaced, and one candidate was rejected outright on fitness. The evidence bar is deliberately high, and the open-weight transition ships as soon as it clears.

Security

Quarterly security audit ran with 28 findings documented, both critical items mitigated same-session. The platform's security policy was further tightened this week. Development-only access paths were removed from production entirely. A pre-publish malware scan was added to the release process, and the platform's machine-readable metadata was standardized with automated verification.

Q2 By the Numbers

  • ~65 blog posts published (5/week, 13 weeks)
  • 3 languages graduated from beta to fully supported (ES, FR, PT)
  • ~150 blog posts translated into 3 languages
  • 6 papers now in the papers library
  • 5 dimension guides completed
  • PAICE Pro Packs launched (5-pack and 10-pack)
  • PAICE Pulse launched as a named product (3-minute confidence check)
  • Purchase-to-access path shipped end-to-end (sign-in, payment, team activation)
  • Entire platform moved onto infrastructure we control directly
  • Three isolated environments stood up (prod / staging / pilot)
  • Automated nightly backups with 30-day retention
  • Outbound email moved to a dedicated delivery service
  • 8 new PAICE Portfolio sites launched (AI Posture, Siteline, ObligationFirst, AI Incident Law, EveryAILaw Pro, PubLedge, GuideCheck, Tokenese)
  • EveryAILaw expanded to 51 instruments across 31 jurisdictions
  • EU Article 50 consultation submitted
  • 28 security findings documented & mitigated
  • Platform security policy tightened across the board
  • Open-weight scoring bake-off completed, final validation under way
  • Open-weight scoring transition shipping soon
  • Various Bug fixes: localized prerender metadata, locale-experience UX, and results/navigation stability
  • 1 unplanned incident across three environments, due to one-time migration issue, mitigated swiftly

Why This Week Matters

This week's content arc — business case, cost of failure, audit trails, accountability — is the buyer-facing sequence that has been building all quarter. Each piece answers a question a different stakeholder asks during procurement. The CFO wants ROI. The CISO wants risk quantification. The compliance officer wants audit trail design. The licensed professional wants to know who carries liability when AI-assisted work fails. Four posts, four questions, four stakeholders. Together they give the internal champion the materials to build the case without needing PAICE in the room.

The security hardening is the kind of work that never appears in a product demo but determines whether a sophisticated buyer's security review passes or stalls. A security policy can look strict while quietly leaving the most dangerous attack vector wide open. Closing that gap is the change that makes "governance-grade" mean something when someone actually inspects how the platform is built.

Thank You

Thank you to everyone who read the buyer-facing content this week and forwarded it to the person in their organization who needed it. The Business Case post was written for the champion who has to build internal support. "The Cost of Getting It Wrong" was written for the CFO who needs the other side of the ROI ledger. The "Audit Trails" post was written for the compliance officer who knows the question is coming. If one of those links landed in the right inbox this week, the distribution model is working.

Q3 starts this week. The open-weight transition ships soon, carrying Q2's benchmark work across the line. What comes next: the foundation that open-weight scoring enables, and the next wave of PAICE Portfolio integrations.


Get Involved:


📖 This Week's Posts:

📖 Other Recent Updates:

Curious but short on time?

Take the 3-minute PAICE Pulse — a quick confidence check that maps how you see your own AI collaboration posture. No login required.