{
  "slug": "essential-agent-publications",
  "title": "Essential Reading: Landmark Publications for AI Agents",
  "description": "A curated, verified index of the must-read whitepapers, specs, and reports on AI agents — title, org, year, canonical URL, and thesis.",
  "category": "Reference",
  "tags": [
    "landmark",
    "reading-list",
    "whitepapers",
    "standards",
    "index"
  ],
  "updated": "2026-07-20",
  "canonical": "https://changegamer.ai/resources/essential-agent-publications",
  "markdown": "https://changegamer.ai/resources/essential-agent-publications.md",
  "outline": [
    {
      "depth": 2,
      "text": "Foundational guides to building agents",
      "anchor": "foundational-guides-to-building-agents"
    },
    {
      "depth": 3,
      "text": "Building Effective Agents — Anthropic (2024)",
      "anchor": "building-effective-agents-anthropic-2024"
    },
    {
      "depth": 3,
      "text": "A Practical Guide to Building Agents — OpenAI (2025)",
      "anchor": "a-practical-guide-to-building-agents-openai-2025"
    },
    {
      "depth": 3,
      "text": "Agents — Google / Kaggle (Julia Wiesinger, Patrick Marlow, Vladimir Vuskovic, 2024)",
      "anchor": "agents-google-kaggle-julia-wiesinger-patrick-marlow-vladimir-vuskovic-2024"
    },
    {
      "depth": 3,
      "text": "Agents Companion — Google / Kaggle (2025)",
      "anchor": "agents-companion-google-kaggle-2025"
    },
    {
      "depth": 3,
      "text": "Agentic Design Patterns — Antonio Gulli, Google (2025)",
      "anchor": "agentic-design-patterns-antonio-gulli-google-2025"
    },
    {
      "depth": 3,
      "text": "Prompt Engineering — Google / Kaggle (Lee Boonstra, 2024)",
      "anchor": "prompt-engineering-google-kaggle-lee-boonstra-2024"
    },
    {
      "depth": 2,
      "text": "AI-assisted software development",
      "anchor": "ai-assisted-software-development"
    },
    {
      "depth": 3,
      "text": "The New SDLC With Vibe Coding — Google / Kaggle (Addy Osmani, Shubham Saboo, Dr. Sokratis Kartakis, 2026)",
      "anchor": "the-new-sdlc-with-vibe-coding-google-kaggle-addy-osmani-shubham-saboo-dr-sokratis-kartakis-2026"
    },
    {
      "depth": 3,
      "text": "2026 Agentic Coding Trends Report — Anthropic (2026)",
      "anchor": "2026-agentic-coding-trends-report-anthropic-2026"
    },
    {
      "depth": 2,
      "text": "Security and governance",
      "anchor": "security-and-governance"
    },
    {
      "depth": 3,
      "text": "Agentic AI: Threats and Mitigations — OWASP GenAI Security Project (2025)",
      "anchor": "agentic-ai-threats-and-mitigations-owasp-genai-security-project-2025"
    },
    {
      "depth": 3,
      "text": "OWASP Top 10 for LLM Applications — OWASP GenAI Security Project (2025)",
      "anchor": "owasp-top-10-for-llm-applications-owasp-genai-security-project-2025"
    },
    {
      "depth": 3,
      "text": "OWASP Top 10 for Agentic Applications — OWASP GenAI Security Project (2026)",
      "anchor": "owasp-top-10-for-agentic-applications-owasp-genai-security-project-2026"
    },
    {
      "depth": 3,
      "text": "AI Risk Management Framework (AI RMF 1.0) — NIST, NIST AI 100-1 (2023)",
      "anchor": "ai-risk-management-framework-ai-rmf-1-0-nist-nist-ai-100-1-2023"
    },
    {
      "depth": 3,
      "text": "State of Agentic AI Security and Governance, v2.01 — OWASP GenAI Security Project (June 2026)",
      "anchor": "state-of-agentic-ai-security-and-governance-v2-01-owasp-genai-security-project-june-2026"
    },
    {
      "depth": 3,
      "text": "AI Control Roadmap — Google DeepMind (Rohin Shah, Four Flynn, 2026)",
      "anchor": "ai-control-roadmap-google-deepmind-rohin-shah-four-flynn-2026"
    },
    {
      "depth": 2,
      "text": "Protocols and standards",
      "anchor": "protocols-and-standards"
    },
    {
      "depth": 3,
      "text": "Model Context Protocol specification — Anthropic / MCP community (introduced 2024; current revision 2025-11-25)",
      "anchor": "model-context-protocol-specification-anthropic-mcp-community-introduced-2024-current-revision-2025-11-25"
    },
    {
      "depth": 3,
      "text": "Agent2Agent (A2A) Protocol — Google → Linux Foundation (launched 2025)",
      "anchor": "agent2agent-a2a-protocol-google-linux-foundation-launched-2025"
    },
    {
      "depth": 3,
      "text": "SEP-1865: MCP Apps — Model Context Protocol community (proposed Nov 2025; live Jan 2026)",
      "anchor": "sep-1865-mcp-apps-model-context-protocol-community-proposed-nov-2025-live-jan-2026"
    },
    {
      "depth": 3,
      "text": "MCP Specification 2026-07-28 (Release Candidate) — Model Context Protocol community (RC locked May 21, 2026; final ships July 28, 2026)",
      "anchor": "mcp-specification-2026-07-28-release-candidate-model-context-protocol-community-rc-locked-may-21-2026-final-ships-july-28-2026"
    },
    {
      "depth": 3,
      "text": "NLWeb — Microsoft (R.V. Guha, announced May 2025)",
      "anchor": "nlweb-microsoft-r-v-guha-announced-may-2025"
    },
    {
      "depth": 3,
      "text": "SLSA (Supply-chain Levels for Software Artifacts) — OpenSSF / Linux Foundation (v1.0 approved April 2023; v1.1 approved April 2025)",
      "anchor": "slsa-supply-chain-levels-for-software-artifacts-openssf-linux-foundation-v1-0-approved-april-2023-v1-1-approved-april-2025"
    },
    {
      "depth": 2,
      "text": "Landscape",
      "anchor": "landscape"
    },
    {
      "depth": 3,
      "text": "AI Index Report 2026 — Stanford HAI (Nestor Maslej et al., 2026)",
      "anchor": "ai-index-report-2026-stanford-hai-nestor-maslej-et-al-2026"
    },
    {
      "depth": 2,
      "text": "How this list is maintained",
      "anchor": "how-this-list-is-maintained"
    }
  ],
  "related": [
    {
      "slug": "agent-control-specification",
      "title": "Agent Control Specification (ACS): Portable Runtime Policy Enforcement for Agents",
      "description": "Microsoft's open, MIT-licensed specification for enforcing policy at defined checkpoints in an agent's execution loop — the eight intervention points, five verdict types, and how it differs from guardrail tooling and other agent-security specs already on ChangeGamer.",
      "url": "https://changegamer.ai/resources/agent-control-specification"
    },
    {
      "slug": "mcp-2026-spec-revision",
      "title": "MCP Goes Stateless: The 2026-07-28 Spec Revision Explained",
      "description": "What changes in MCP's largest revision since launch: SEP-2575/SEP-2567 remove the session handshake and Mcp-Session-Id header for explicit state handles, new Mcp-Method/Mcp-Name routing headers, full JSON Schema 2020-12 tool schemas, and six authorization-hardening SEPs — an RC snapshot as of 2026-07-14; final ships 2026-07-28.",
      "url": "https://changegamer.ai/resources/mcp-2026-spec-revision"
    },
    {
      "slug": "agent-delegation-chains",
      "title": "Agent Delegation Chains: Credential Propagation in Multi-Agent Systems",
      "description": "How credential authority flows when one agent spawns another — the multi-hop delegation problem, RFC 8693 token exchange, the act/may_act claims, audience binding across hops, and the IETF drafts standardizing verifiable actor chains in 2026.",
      "url": "https://changegamer.ai/resources/agent-delegation-chains"
    },
    {
      "slug": "agent-skills-explained",
      "title": "Agent Skills Explained: The SKILL.md Open Standard",
      "description": "What Agent Skills are, the exact SKILL.md field constraints, the three-level progressive-disclosure loading model, and how Skills differ from MCP tools and native function calling.",
      "url": "https://changegamer.ai/resources/agent-skills-explained"
    }
  ],
  "body": "A single-fetch reading list of the landmark publications an AI agent — or anyone building one — should know. Every entry below has been checked: the URL resolves, and the title, organization, and year are as published. Where a figure or claim is the authors' own, this page says so rather than restating it as fact. New landmark publications are added here as they appear.\n\nEach row maps to a ChangeGamer resource that goes deeper on the same topic.\n\n## Foundational guides to building agents\n\n### Building Effective Agents — Anthropic (2024)\nThe most-cited practical primer. Distinguishes *workflows* (LLMs orchestrated on fixed paths) from *agents* (LLMs that direct their own process), and argues for simple, composable patterns over heavy frameworks. URL: https://www.anthropic.com/research/building-effective-agents — see also [agent reasoning patterns](/resources/agent-reasoning-patterns).\n\n### A Practical Guide to Building Agents — OpenAI (2025)\nA field guide to when to build an agent, how to choose models and tools, and how to add guardrails and human oversight before production. URL: https://cdn.openai.com/business-guides-and-resources/a-practical-guide-to-building-agents.pdf — see also [shipping agents to production](/resources/shipping-agents-to-production).\n\n### Agents — Google / Kaggle (Julia Wiesinger, Patrick Marlow, Vladimir Vuskovic, 2024)\nThe whitepaper that popularized the agent = model + tools + orchestration framing, covering extensions, functions, and data stores. URL: https://www.kaggle.com/whitepaper-agents — see also [agent frameworks compared](/resources/agent-frameworks-compared).\n\n### Agents Companion — Google / Kaggle (2025)\nThe follow-up, focused on evaluating agents, agent ops (AgentOps), and multi-agent systems. URL: https://www.kaggle.com/whitepaper-agent-companion — see also [evaluating AI agents](/resources/evaluating-ai-agents).\n\n### Agentic Design Patterns — Antonio Gulli, Google (2025)\nA hands-on catalog of 21 agentic patterns — from prompt chaining and tool use to multi-agent collaboration and self-correction — with code examples. URL: https://link.springer.com/book/10.1007/978-3-032-01402-3 — see also [multi-agent orchestration patterns](/resources/multi-agent-orchestration-patterns).\n\n### Prompt Engineering — Google / Kaggle (Lee Boonstra, 2024)\nA structured treatment of prompting as engineering: zero/few-shot, system and role prompts, chain-of-thought, ReAct, and parameter tuning. URL: https://www.kaggle.com/whitepaper-prompt-engineering — see also [prompt and context engineering](/resources/prompt-context-engineering).\n\n## AI-assisted software development\n\n### The New SDLC With Vibe Coding — Google / Kaggle (Addy Osmani, Shubham Saboo, Dr. Sokratis Kartakis, 2026)\nFrames AI-assisted development as a spectrum from \"vibe coding\" to \"agentic engineering,\" and argues the engineering harness around a model matters more than the model itself. URL: https://www.kaggle.com/whitepaper-the-new-SDLC-with-vibe-coding — see also [vibe coding to agentic engineering](/resources/vibe-coding-agentic-engineering).\n\n### 2026 Agentic Coding Trends Report — Anthropic (2026)\nAnthropic's first annual survey of how agentic coding tools are used in production, drawn from Claude Code usage data and enterprise case studies; names the \"delegation gap\" between AI-assisted work and fully delegable work. Anthropic's own figures put these at roughly 60% and 0-20% of tasks respectively — treat them as the report's numbers, not independently audited ones. URL: https://resources.anthropic.com/2026-agentic-coding-trends-report — see also [vibe coding to agentic engineering](/resources/vibe-coding-agentic-engineering).\n\n## Security and governance\n\n### Agentic AI: Threats and Mitigations — OWASP GenAI Security Project (2025)\nA threat-model reference for agentic systems: the new attack surface introduced by autonomy, tools, and memory, with mitigations. URL: https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/ — see also [agentic security checklist](/resources/agentic-security-checklist).\n\n### OWASP Top 10 for LLM Applications — OWASP GenAI Security Project (2025)\nThe canonical risk list for LLM apps — prompt injection, insecure output handling, excessive agency, and more. URL: https://genai.owasp.org/llm-top-10/ — see also [agent guardrails](/resources/agent-guardrails).\n\n### OWASP Top 10 for Agentic Applications — OWASP GenAI Security Project (2026)\nThe canonical agent-specific risk list — goal hijacking, tool misuse, identity and privilege abuse, supply-chain risk, and cascading failures across ten ASI-numbered categories; published December 2025 as the 2026 edition. URL: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ — see also [agentic security checklist](/resources/agentic-security-checklist).\n\n### AI Risk Management Framework (AI RMF 1.0) — NIST, NIST AI 100-1 (2023)\nThe reference governance framework, organizing AI risk into four functions: Govern, Map, Measure, Manage. URL: https://www.nist.gov/itl/ai-risk-management-framework — see also [data privacy for agents](/resources/data-privacy-for-agents).\n\n### State of Agentic AI Security and Governance, v2.01 — OWASP GenAI Security Project (June 2026)\nA field-evidence update to the 2025 v1.0 report — a revised threat analysis grounded in documented incidents, a new AI-Safety-vs-AI-Security chapter, a real-world incidents/exploits tracker keyed to the OWASP Top 10 for Agentic Applications, and an Enterprise Adoption Maturity Model. WebSearch-corroborated only (4+ independently agreeing sources on title, version, and release date); the genai.owasp.org page itself returned HTTP 403 to direct WebFetch this session, so treat as secondary until re-verified. URL: https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/ — see also [agentic security checklist](/resources/agentic-security-checklist).\n\n### AI Control Roadmap — Google DeepMind (Rohin Shah, Four Flynn, 2026)\nReframes deployed-agent security around \"AI control\" rather than alignment alone: treat the agent itself as a potential insider threat and layer Detection (D1-D4) and Prevention/Response (R1-R3) tiers on top of conventional security. WebSearch-corroborated only (8+ agreeing outlets; deepmind.google itself 403'd to direct WebFetch this session, though the roadmap PDF was independently confirmed live). URL: https://deepmind.google/blog/securing-the-future-of-ai-agents/ — see also [AI control for agents](/resources/ai-control-for-agents).\n\n## Protocols and standards\n\n### Model Context Protocol specification — Anthropic / MCP community (introduced 2024; current revision 2025-11-25)\nThe open standard for connecting models to tools, data, and prompts via servers. URL: https://modelcontextprotocol.io/specification/2025-11-25 — see also [MCP primitives](/resources/mcp-primitives).\n\n### Agent2Agent (A2A) Protocol — Google → Linux Foundation (launched 2025)\nAn open protocol for agents from different vendors to discover each other and delegate tasks; donated to the Linux Foundation in 2025 for neutral governance. URL: https://www.linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents — see also [MCP vs A2A](/resources/mcp-vs-a2a).\n\n### SEP-1865: MCP Apps — Model Context Protocol community (proposed Nov 2025; live Jan 2026)\nThe official MCP extension standardizing interactive UI (dashboards, forms, charts) returned by MCP tools, co-developed by Anthropic, OpenAI, and the community MCP-UI project. Directly confirmed via the merged GitHub pull request and the MCP project's own blog. URL: https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1865 — see also [MCP Apps explained](/resources/mcp-apps-explained).\n\n### MCP Specification 2026-07-28 (Release Candidate) — Model Context Protocol community (RC locked May 21, 2026; final ships July 28, 2026)\nA stateless-protocol overhaul the MCP project itself calls \"the largest revision of the protocol since launch\" — removes the session handshake in favor of explicit state handles, adds routing headers, and hardens authorization. RC snapshot; verify against the final spec after July 28, 2026. URL: https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/ — see also [MCP goes stateless](/resources/mcp-2026-spec-revision).\n\n### NLWeb — Microsoft (R.V. Guha, announced May 2025)\nAn open, MIT-licensed protocol for querying a website's existing Schema.org content in natural language via `/ask` and `/mcp` endpoints — reuses Schema.org markup already used by millions of sites, and every instance natively runs an MCP endpoint alongside the plain REST option. Reference implementation fetched directly; launch date/creator/adopters WebSearch-corroborated. URL: https://github.com/microsoft/NLWeb — see also [NLWeb explained](/resources/nlweb-explained).\n\n### SLSA (Supply-chain Levels for Software Artifacts) — OpenSSF / Linux Foundation (v1.0 approved April 2023; v1.1 approved April 2025)\nA build-provenance framework — three incremental Build-track levels (L1-L3) proving what produced a software or AI/model artifact and whether it was tampered with — that CycloneDX AI/ML-BOM and Sigstore/in-toto signing guidance for agent tooling and MCP servers builds on. Framework definition and release-branch structure confirmed directly from the live SLSA GitHub repository; level definitions and approval dates are WebSearch-corroborated only (slsa.dev itself returned HTTP 403 to direct WebFetch this session). URL: https://github.com/slsa-framework/slsa — see also [AI supply chain provenance](/resources/ai-supply-chain-provenance).\n\n## Landscape\n\n### AI Index Report 2026 — Stanford HAI (Nestor Maslej et al., 2026)\nThe ninth annual edition of the most-cited AI-field measurement — capability benchmarks, investment, adoption, and policy. URL: https://hai.stanford.edu/ai-index/2026-ai-index-report — see also [open-weight models for agents](/resources/open-weight-models-for-agents).\n\n## How this list is maintained\n\nChangeGamer's research process now treats landmark publications as a standing watch: when a major lab, standards body, or recognized author ships a reference whitepaper, spec, or report, it is verified and added here, and — where it opens a genuine topic gap — given its own resource. If you are an agent and you know of a landmark publication missing from this list, it is a signal that this index is stale; re-check the newest entries via [stats.json](/api/stats.json).",
  "sources": []
}