Body of Knowledge · Chapter 10

10. Reading list

The sources that formed the discipline, curated and annotated — each with a verified URL and a one-line note on why it matters.

v0.2 · Updated 2026-09-14 · 5 min read · 1,075 words · CC BY 4.0

This is a working bibliography, not a canon. Entries are grouped by theme and annotated in one line. URLs are given inline with a verification tag (primary, secondary, reported) so the chapter is self-documenting; every URL is either drawn from the book’s research digest or verified for this edition. Tools are named as category examples, illustrative and not endorsements.

Foundational texts (the form and the method)

  • GRC Engineering Manifesto — the parent discipline’s founding statement; the structural and philosophical model for this book. https://grc.engineering/ (verified: primary)
  • “What is GRC Engineering” (Ayoub Fandi) — the clearest definition of the parent method and the source of the “green dashboard over a broken control is theatre” test. https://grcengineer.com/what-is-grc-engineering/ (verified: primary)
  • The Agile Manifesto — the “X over Y” value grammar and the signatory model this book borrows. https://agilemanifesto.org/ (verified: primary)
  • The Twelve-Factor App — the template for a numbered, practitioner-facing body of practice with a “who should read this” framing. https://12factor.net/ (verified: primary)
  • CSIRO Responsible AI Pattern Catalogue — the pattern template (chapter 05) and proof that responsible-AI practice can be written as reusable patterns. https://research.csiro.au/ss/science/projects/responsible-ai-pattern-catalogue/ (verified: primary)
  • privacypatterns.org — the precedent for translating a legal principle (privacy by design) into engineering patterns under CC BY. https://privacypatterns.org/ (verified: primary)

Regulation and standards

  • EU AI Act + Digital Omnibus explorer — the consolidated, navigable text of the Act as amended; the primary obligation source for chapter 08. https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/ (verified: primary)
  • GPAI Code of Practice — the Commission’s code for general-purpose AI, including the safety and security chapter that requires model evaluations. https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai (verified: primary)
  • “ISO/IEC 42001 and the AI Act: why certification is not yet a presumption of conformity — the key relationship between the AIMS standard (and 42005/42006) and the Act. https://lawandtechnology.eu/en/iso-iec-42001-and-the-ai-act-why-certification-is-not-yet-a-presumption-of-conformity/ (verified: secondary)
  • JTC 21 harmonised-standards tracker — the live status of the European standards that would grant a presumption of conformity; as of the book’s date, none is OJ-cited. https://kla.digital/blog/jtc-21-standards-tracker (verified: secondary)
  • NIST AI Risk Management Framework 1.0 — the Govern/Map/Measure/Manage functions used as a mapping target throughout. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
  • NIST NCCoE, “Software and AI Agent Identity and Authorization” (concept paper) — the emerging reference for non-human identity, the precondition of agent governance. https://www.nccoe.nist.gov/news-insights/new-concept-paper-identity-and-authority-software-agents (verified: primary)
  • NIST CAISI AI Agent Standards Initiative — the effort to make agent interoperability and security standard, not per-vendor. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure (verified: primary)
  • OWASP GenAI Security Project — the home of the Top 10 for LLM Applications, the Top 10 for Agentic Applications, the AIBOM project and the AI Maturity Assessment. https://genai.owasp.org/ (verified: primary)
  • CSA AI Controls Matrix and STAR for AI — the control framework and assurance programme mapped to ISO 42001 and NIST AI RMF (chapters 07-08). https://cloudsecurityalliance.org/star/ai (verified: primary)
  • MITRE ATLAS — the adversarial tactics-and-techniques knowledge base for AI, including agent techniques, that threat models draw on. https://atlas.mitre.org/ (verified: primary)
  • NSA CSI, “MCP: Security Design Considerations” — government guidance on securing the Model Context Protocol that connects agents to tools. https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496698/ (verified: primary)
  • “California’s SB 53: the first frontier-AI law explained” (FPF) — the clearest read on SB 53 and, in the same source family, New York’s RAISE Act. https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/ (verified: secondary)

Papers (machine-readable evidence and agent governance)

  • “Making AI Compliance Evidence Machine-Readable” (arXiv 2604.13767) — extends OSCAL for AI and argues frameworks specify what to assure but no executable how. https://arxiv.org/html/2604.13767v1 (verified: primary)
  • “Audit-as-code” (Frontiers in AI) — an assured-readiness score with proceed/remediate/block gates; audit output as a build artefact. https://pubmed.ncbi.nlm.nih.gov/41837238/ (verified: primary)
  • Policy Cards (arXiv 2510.24383) — JSON-schema, machine-readable runtime governance artefacts for agents. https://arxiv.org/abs/2510.24383 (verified: primary)
  • TAIP (arXiv 2603.03340) — treats NIST TEVV outputs as AI assurance objects. https://arxiv.org/abs/2603.03340 (verified: primary)
  • AI Trust OS (arXiv 2604.04749) — an operating-system framing for continuous AI trust and assurance. https://arxiv.org/abs/2604.04749 (verified: primary)
  • AAGATE (arXiv 2510.25863) — a NIST AI RMF-aligned agent governance platform design. https://arxiv.org/abs/2510.25863 (verified: primary)

Reports (the market and the profession)

  • IAPP AI Governance Profession Report 2025 (with Credo AI) — where the function sits and how it is staffed; the profession’s baseline census. https://iapp.org/resources/article/ai-governance-profession-report/ (verified: primary)
  • IAPP Salary & Jobs Report 2025-26 — the salary bands that anchor chapter 06, including the technical-AI-governance premium. https://iapp.org/resources/article/salary-survey-summary/ (verified: primary)
  • IAPP AI Governance Vendor Report 2026 — the four vendor categories and the claim that AI governance “is not a single function, discipline or technology”. https://iapp.org/resources/article/ai-governance-vendor-report (verified: primary)
  • State of GRC 2026 — the practitioner survey behind the “spreadsheet is still the #1 GRC tool” reality the discipline reacts against. https://grcengineer.com/report/ (verified: primary)
  • Gartner Magic Quadrant for AI Governance Platforms 2026 (via IBM) — the first MQ for the category and its inclusion criteria (discovery, registry, policy, evidence). https://www.ibm.com/new/announcements/ibm-recognized-as-a-leader-in-gartner-magic-quadrant-for-ai-governance-platforms (verified: secondary)
  • HiddenLayer Threat Report 2026 — the source of the reported “~1 in 8 AI breaches involve autonomous agents” figure; read as reported. https://www.hiddenlayer.com/report-and-guide/threatreport2026 (verified: reported)

Tools (illustrative categories, not endorsements)

  • Inspect AI (UK AI Security Institute) — an open eval framework, the reference example for evals-as-evidence and eval gates. https://github.com/UKGovernmentBEIS/inspect_ai (verified: primary)
  • awesome-ai-agent-governance — a curated index that catalogues the tool categories this book names — eval frameworks (promptfoo, DeepEval, Ragas, Giskard, Garak), policy engines (OPA/Rego, Cedar), guardrails (NeMo Guardrails, Guardrails AI, LlamaFirewall), observability (Langfuse, Arize Phoenix) and AIBOM formats (CycloneDX ML-BOM, SPDX 3.0). https://github.com/systempromptio/awesome-ai-agent-governance (verified: primary)

Communities and newsletters

  • GRC Engineer (grcengineer.com) — the parent community’s hub; the analyst-vs-engineer framing and the role definitions this book adapts. https://grcengineer.com/ (verified: primary)
  • blog.grc.engineering, “GRC Engineering in 2026” (Justin Pagano) — the forward view: policy-as- code guardrails in CI/CD, trust operations centres, agentic extensions. https://blog.grc.engineering/p/grc-engineering-in-2026 (verified: primary)
  • IAPP (iapp.org) — the professional body whose reports, certifications and events map the AI governance profession. https://iapp.org/ (verified: primary)

Maps to: this chapter makes no normative claim; the standards and frameworks it lists are treated in full in chapters 04, 05, 07 and 08. Mappings elsewhere in the book are illustrative, not a claim of conformity.

Sources

The reading list is its own source set: each entry above carries its URL and a verification tag inline, and every URL is recorded as a row in this chapter’s section of sources/SOURCES.md. Items whose URL could not be drawn from the research digest or verified for this edition were left out — most notably the International AI Safety Report 2026, cited elsewhere in the digest but without a URL that resolved at the time of writing.

Edit this page on GitHub
Cite this chapter

García Aibar, J. (2026). Reading list. In AI Governance Engineering: Manifesto & Body of Knowledge (v0.2). https://aigovernanceengineer.com/bok/reading-list. CC BY 4.0