Reading list: primary sources worth bookmarking
17 places to go when you want the original document instead of the coverage. Every link was opened and checked on . Inclusion is not endorsement. Vendor-written sources are marked as such.
Regulation and guidance
AI Act implementation timeline
European Commission, AI Act Service Desk
The Commission's own calendar of application dates, updated after the 2026 amending regulation, so the first place to check a deadline.
AI Act policy page
European Commission
A plain overview of the risk-based approach and the current state of the law from the institution that proposed it.
Guidelines for providers of general-purpose AI models
European Commission
Explains what model providers must do and when enforcement powers begin, which tells buyers what to expect from suppliers.
Code of Practice on marking and labelling AI-generated content
European Commission
The voluntary code behind the Article 50 transparency rules, useful for anyone publishing synthetic media.
Legislative Train: Digital Omnibus on AI
European Parliament
The procedural record of how the 2026 changes were proposed, voted and adopted, with dates.
Guidance on AI and data protection
Information Commissioner's Office (UK)
The UK regulator's guidance on applying data protection law to AI systems, including a risk toolkit.
AI Risk Management Framework
National Institute of Standards and Technology (US)
A voluntary framework that many organisations use as a common vocabulary for AI risk, with a generative AI profile.
Agents and security
Model Context Protocol specification
Model Context Protocol project
The actual protocol text, including a candid security section on what the protocol cannot enforce.
MCP governance and stewardship
Model Context Protocol project
Shows who holds decision rights over the protocol, which matters more than any press release about openness.
Prompt injection is not SQL injection
National Cyber Security Centre (UK)
The clearest official explanation of why prompt injection may never be fully fixed and how to design around it.
LLM01: Prompt Injection
OWASP Gen AI Security Project
A practitioner-maintained description of the top-ranked risk for language model applications, with mitigations.
Evaluation and evidence
Time horizons
METR
Tracks how long a task AI systems can complete. It is unusually frank about the limits of its own measure.
Inspect
UK AI Security Institute
An open-source evaluation framework from a government body, useful for seeing how serious evaluations are built.
Draft NIST AI 800-2: automated benchmark evaluations
National Institute of Standards and Technology (US)
Draft voluntary practices for running and reporting benchmarks, written partly for people who read the results.
International AI Safety Report
Expert panel chaired by Yoshua Bengio
A multi-country scientific review of what general-purpose AI can do and where the risks are, written for policymakers.
AI Index Report 2026
Stanford Institute for Human-Centered AI
The broadest annual collection of data on AI performance, investment and adoption, with sources for each chart.
System cards
Anthropic
An example of model documentation from a developer. It is long and vendor-written but it is where evaluation setups are disclosed.
How these are used
My notes are built on these sources, starting with the EU AI Act timeline. If a link here breaks or a better primary source exists, please tell me through the contact form.
AI strategy / Implementation / Training
Work with me
For businesses that want AI built into their day-to-day work. It starts with a free 30-minute discovery call.