Reference
References
Every source cited across the topic catalog, consolidated and alphabetized. Sources are primary documentation, standards bodies, peer-reviewed or preprint research, and named engineering organizations' own published data: not marketing content, SEO content, or generic consultant thought leadership. This list is a lookup appendix; the in-context citation for each source appears under the relevant topic's "Recommended Learning" entry in the catalog.
- A Timeline of Model Context Protocol (MCP) Security Breaches
- A2A and MCP: A2A Protocol
- A2A Protocol Surpasses 150 Organizations...: Linux Foundation
- Access Foundry Models and Other Language Models Through a Gateway: Azure Architecture Center
- Activating your internal AI champions (GitHub)
- Agent Authority Least Privilege Framework: FINOS
- Agentic AI: Threats and Mitigations
- AgentOps: Enabling Observability of LLM Agents (arXiv)
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
- agents.md: the open standard
- AI Act: Shaping Europe's digital future (European Commission)
- AI Agents as Users: Nielsen Norman Group
- AI Agents Have an Authorization Problem, Not Just an Identity Problem
- AI Chatbots Discourage Error Checking: Nielsen Norman Group
- AI gateway capabilities in Azure API Management
- AI Red Teaming Initiative: OWASP Gen AI Security Project
- AI Risk Management Framework (NIST)
- AI RMF: Generative Artificial Intelligence Profile (NIST)
- Announcing Microsoft Entra Agent ID
- Anthropic: Claude Code best practices
- Anthropic: Effective harnesses for long-running agents
- Anthropic: How we built our multi-agent research system
- appleinsider.com
- Article 4: AI literacy: EU Artificial Intelligence Act
- Auditing and Logging AI Agent Activity: A Guide for Engineers: LoginRadius Engineering Blog
- Authorization and Governance for AI Agents: Runtime Authorization Beyond Identity at Scale
- Bersin
- BIRD-SQL benchmark
- Block denied topics to help remove harmful content: Amazon Bedrock
- Building Effective AI Agents: Anthropic
- Canaries Dashboard (Stanford Digital Economy Lab)
- Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of AI (Stanford Digital Economy Lab)
- Chargeback vs. Showback: Cloud Cost Allocation Models Explained: CloudZero
- Claude Enterprise
- Claude prompting best practices (Claude Platform Docs)
- Cloud Security Alliance: The Vibe Coding Governance Gap
- cloud.google.com
- Computer use tool: Claude Platform Docs
- Computer-Using Agent: OpenAI
- Contextual Retrieval (Anthropic)
- deloitte.com
- Deloitte: The State of AI in the Enterprise
- developers.googleblog.com
- Diving Into the MCP Authorization Specification: Descope
- Donating the Model Context Protocol and establishing the Agentic AI Foundation: Anthropic
- DORA 2025: State of AI-assisted Software Development
- DORA AI Capabilities Model report
- DORA Insights
- DORA research on AI
- DORA: Balancing AI tensions: moving from adoption to effective SDLC use
- Effective context engineering for AI agents: Anthropic
- en.wikipedia.org
- Enterprise AI Operating Model: Hub-and-Spoke, Federated, or Centralized?
- EU agrees Digital Omnibus deal to simplify AI rules: White & Case
- EU AI Act implementation timeline: AI Act Service Desk
- Explainable AI in Chat Interfaces: Nielsen Norman Group
- Factory.ai: From coding agents to software factories
- Fine-tuning (OpenAI Developers guide)
- FinOps for AI Overview: FinOps Foundation
- Forrester
- Gartner
- Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026
- gartner.com
- Gemini 3: Introducing the latest Gemini AI model (Google)
- Generative AI at Work: Brynjolfsson, Li, Raymond (NBER Working Paper 31161)
- Generative Artificial Intelligence and Copyright Law: Congressional Research Service
- GitClear: AI Copilot Code Quality 2025 research
- GitHub MCP Exploited: Accessing private repositories via MCP
- GitHub Octoverse 2025
- GitHub Octoverse 2025
- Glean
- Glean
- Google Cloud
- Google: NotebookLM Adds Deep Research
- GPT-5.1 System Card Addendum (OpenAI)
- GraphRAG: Unlocking LLM discovery on narrative private data (Microsoft Research)
- HHEM v2: A New and Improved Factual Consistency Scoring Model: Vectara
- How we built our multi-agent research system: Anthropic
- Hybrid search (Weaviate Documentation)
- Identifying Token Costs Hiding in Your Agentic Loop: MachineLearningMastery
- InfoQ: Agentic fitness functions: extending evolutionary architecture beyond deterministic rules
- InfoWorld: How Google is using LLMs for complex internal code migrations
- Inside the LLM Call: GenAI Observability with OpenTelemetry: OpenTelemetry Blog
- Introducing Claude Opus 4.5 (Anthropic)
- Introducing the Model Context Protocol (Anthropic)
- Introduction: Model Context Protocol
- ISO/IEC 42001 explained
- ISO/IEC 42001:2023: AI management systems
- ISO/IEC 42001:2023: Microsoft compliance overview
- Judging LLM-as-a-Judge with MT-Bench and Chatbot Arena (arXiv)
- learn.microsoft.com
- Least privilege for AI agents with Microsoft Entra Agent ID
- Least privilege for AI agents: Identity, access, and tool binding
- Levels of Autonomy for AI Agents: Knight First Amendment Institute
- Leveraging model distillation to fine-tune a model (OpenAI Cookbook)
- Llama 4 Community License Agreement
- LLM Agent Evaluation Metrics: Tool Calling, Task Completion, Reasoning, and Trace-Based Evals: Confident AI
- LLM Evaluation: Best Practices and Methods: Databricks Engineering Blog
- LLM Routing and Model Cascades: How to Cut AI Costs Without Sacrificing Quality
- LLMOps Guide: Build Fast, Cost-Effective LLM Apps: Redis Engineering Blog
- MCP Authorization specification
- MCP Security Notification: Tool Poisoning Attacks: Invariant Labs
- MCP Tool Poisoning: OWASP Foundation
- Measuring AI agent autonomy in practice: Anthropic
- MemGPT: Towards LLMs as Operating Systems (arXiv)
- Memory for Claude Managed Agents (Anthropic)
- merics.org
- Meta's Llama license is still not Open Source (Open Source Initiative)
- METR: Measuring the impact of AI on experienced open-source developer productivity
- Microsoft Agent 365 Overview
- Microsoft GraphRAG project page
- Microsoft Learn: Overview of Process Mining in Power Automate
- Microsoft Support: Use Researcher in Copilot Notebooks
- Microsoft: Catch Up on Meetings with Copilot in Teams
- Migrating Code At Scale With LLMs At Google (arXiv 2504.09691, FSE 2025)
- MIT NANDA
- MIT report: 95% of generative AI pilots at companies are failing
- Model router for Microsoft Foundry: concepts
- n8n Docs
- NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative AI Profile
- NIST AI RMF Playbook
- NSA/CISA: Model Context Protocol (MCP) Security
- One Year of MCP (Model Context Protocol blog)
- OpenAI
- OpenTelemetry GenAI Semantic Conventions: MLflow documentation
- OSWorld 2.0 (arXiv 2606.29537)
- Overview of model routing: Google Cloud API Gateway
- OWASP Gen AI Security Project: Resources
- OWASP LLM01:2025 Prompt Injection
- OWASP LLM04:2025 Data and Model Poisoning
- OWASP LLM05:2025 Improper Output Handling
- OWASP LLM06:2025 Excessive Agency
- OWASP LLM08:2025 Vector and Embedding Weaknesses
- OWASP Top 10 for LLM Applications 2025
- OWASP Top 10 for LLM Applications 2025
- pgvector (GitHub)
- Prompt engineering best practices for 2026 (Anthropic)
- Prompt injection: Wikipedia
- RAG Security Cheat Sheet (OWASP)
- RAG with Permissions (Supabase Docs)
- RAGAS: Automated Evaluation of Retrieval Augmented Generation (arXiv)
- ReAct: Synergizing Reasoning and Acting in Language Models
- Regulation (EU) 2024/1689 (EUR-Lex, official text)
- Remove PII from conversations by using sensitive information filters
- Replay: reconstructing an agent action from the audit log: Deixic
- research.google
- Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks (Lewis et al., 2020)
- Rising AI Adoption Spurs Workforce Changes (Gallup)
- Safety and content filters: Vertex AI
- salesforce.com
- salesforce.com
- Salesforce: Agentforce Developer Guide: Get Started
- Securing Agentic Applications Guide 1.0
- Security Degradation in Iterative AI Code Generation (arXiv 2506.11022, IEEE ISTAS 2025)
- Security, Guardrails, and Observability in Amazon Bedrock
- Shadow deployment vs. canary release of machine learning models
- Simon Willison's prompt-injection archive
- SPIFFE: Securing the identity of agentic AI and non-human actors
- State of UX 2026: Nielsen Norman Group
- stripe.com
- Structured Outputs (OpenAI API)
- Team Topologies as the "infrastructure for agency" with AI
- Team Topologies: the book's site
- Techzine
- The 2026 MCP Roadmap: Model Context Protocol Blog
- The AI Champion role (OpenAI Academy)
- The lethal trifecta for AI agents
- The New York Times v. Microsoft and OpenAI: case background and status
- The Non-Human Identity Governance Vacuum
- The Register, "AI coding tools make developers slower, study finds"
- The State of AI: Global Survey 2025 (McKinsey)
- The Vulnerable MCP Project
- Token Economics: The Atomic Unit of AI Value: FinOps Foundation
- Tool use with Claude: Claude Platform Docs
- TRAJECT-Bench: A Trajectory-Aware Benchmark for Evaluating Agentic Tool Use (arXiv)
- UiPath
- UiPath: What is Agentic Orchestration?
- Understanding intelligent prompt routing in Amazon Bedrock
- Understanding the context window (Anthropic docs)
- US Supreme Court declines to consider whether AI alone can create copyrighted works: Morgan Lewis
- vectara/hallucination-leaderboard (GitHub)
- When Should We Trust AI? Magic-8-Ball Thinking and AI Hallucinations: Nielsen Norman Group
- Workato: Agentic (docs)