Skip to content
Frank Vitetta

Reading list: primary sources worth bookmarking

17 places to go when you want the original document instead of the coverage. Every link was opened and checked on . Inclusion is not endorsement. Vendor-written sources are marked as such.

Regulation and guidance

  1. AI Act implementation timeline

    European Commission, AI Act Service Desk

    The Commission's own calendar of application dates, updated after the 2026 amending regulation, so the first place to check a deadline.

  2. AI Act policy page

    European Commission

    A plain overview of the risk-based approach and the current state of the law from the institution that proposed it.

  3. Guidelines for providers of general-purpose AI models

    European Commission

    Explains what model providers must do and when enforcement powers begin, which tells buyers what to expect from suppliers.

  4. Code of Practice on marking and labelling AI-generated content

    European Commission

    The voluntary code behind the Article 50 transparency rules, useful for anyone publishing synthetic media.

  5. Legislative Train: Digital Omnibus on AI

    European Parliament

    The procedural record of how the 2026 changes were proposed, voted and adopted, with dates.

  6. Guidance on AI and data protection

    Information Commissioner's Office (UK)

    The UK regulator's guidance on applying data protection law to AI systems, including a risk toolkit.

  7. AI Risk Management Framework

    National Institute of Standards and Technology (US)

    A voluntary framework that many organisations use as a common vocabulary for AI risk, with a generative AI profile.

Agents and security

  1. Model Context Protocol specification

    Model Context Protocol project

    The actual protocol text, including a candid security section on what the protocol cannot enforce.

  2. MCP governance and stewardship

    Model Context Protocol project

    Shows who holds decision rights over the protocol, which matters more than any press release about openness.

  3. Prompt injection is not SQL injection

    National Cyber Security Centre (UK)

    The clearest official explanation of why prompt injection may never be fully fixed and how to design around it.

  4. LLM01: Prompt Injection

    OWASP Gen AI Security Project

    A practitioner-maintained description of the top-ranked risk for language model applications, with mitigations.

Evaluation and evidence

  1. Time horizons

    METR

    Tracks how long a task AI systems can complete. It is unusually frank about the limits of its own measure.

  2. Inspect

    UK AI Security Institute

    An open-source evaluation framework from a government body, useful for seeing how serious evaluations are built.

  3. Draft NIST AI 800-2: automated benchmark evaluations

    National Institute of Standards and Technology (US)

    Draft voluntary practices for running and reporting benchmarks, written partly for people who read the results.

  4. International AI Safety Report

    Expert panel chaired by Yoshua Bengio

    A multi-country scientific review of what general-purpose AI can do and where the risks are, written for policymakers.

  5. AI Index Report 2026

    Stanford Institute for Human-Centered AI

    The broadest annual collection of data on AI performance, investment and adoption, with sources for each chart.

  6. System cards

    Anthropic

    An example of model documentation from a developer. It is long and vendor-written but it is where evaluation setups are disclosed.

How these are used

My notes are built on these sources, starting with the EU AI Act timeline. If a link here breaks or a better primary source exists, please tell me through the contact form.

AI strategy / Implementation / Training

Work with me

For businesses that want AI built into their day-to-day work. It starts with a free 30-minute discovery call.