Library¶
The library is the provenance store for the best practices. Everything used to model a practice, whether it supported, qualified, or contradicted a claim, is recorded here so a reader can check it. It has two tiers.
Distilled sources are rich documents (strategy papers, policy reports, institutional documents) reduced into the passages that matter, with locators and a mapping to the practices. Reference works are the standards, papers, reports, and guidance cited as point support, each a short bibliographic record.
Raw documents are not hosted here. Each entry carries a full citation to the
original. The atom-level record of which source bears on which practice line, and
whether it is for or against, lives in the provenance data (assets/provenance.yml).
Distilled sources¶
| Document | Issuing body | Date | Role in the record |
|---|---|---|---|
| ELIXIR TF Agentic AI: agenda and rolling best practice | ELIXIR Europe, AI Ecosystem Focus Group | 2026 | Main source for the provider-facing practices (BP02, BP03, BP05, BP06, BP07, BP09); also seeds BP08 (evaluation). |
| Agentic AI in the higher-education system | Hochschulforum Digitalisierung / KI-Campus | May 2026 | Main source for the governance practice (BP04); grounds several others. |
| EU Expert Forum on Frontier AI | European Commission, European AI Office | July 2026 | Largely out of scope; grounds BP01, BP03, BP04, BP07 on method choice, evaluation, and provider choice. |
| ELIXIR AI strategy | ELIXIR Europe | June 2026 | Largely organisational; grounds BP05, BP07, BP08 on curated data, provenance, and validation. |
| The GenAI Divide | MIT Project NANDA | July 2025 | Out-of-domain enterprise report; grounds BP01, BP06, BP08 on task fit, workflow design, and outcome-based evaluation; qualifies BP03. |
| Expectation–Realisation Gap for Agentic AI | Lobentanzer (Helmholtz Munich) | February 2026 | Review of controlled trials on realised vs expected benefit; downweighted context (author is a contributor); grounds BP01 on heterogeneity and benefit planning, with optional context for BP06, BP08, BP09. |
| EU AI Omnibus | European Union | July 2026 | Largely out-of-scope regulatory simplification of the AI Act; grounds BP04 and BP10 on technical safeguards against foreseeable misuse, with context for BP03, BP08. |
| A safer framework for patient data in AI-for-Science grants | Gagneur (TU Munich) | July 2026 | Individual commentary on grant data terms; grounds BP04, BP02, BP09 on data-egress control, governed access, and effective oversight; flags a gap on controlled-access data in third-party training. |
Reference works¶
The standards, papers, and reports cited by the practices, grouped by theme. Each links to its bibliographic record.
Method selection
- Building Effective AI Agents (Anthropic 2024)
- AI Agents That Matter (Kapoor et al. 2024)
- Fine-tuned small LLMs beat zero-shot frontier models (Bucher & Martini 2024)
- Leakage and the reproducibility crisis in ML-based science (Kapoor & Narayanan 2023)
Data and metadata standards
- FAIR Guiding Principles (2016)
- ELIXIR Core Data Resources (2020)
- bio.tools registry (2019)
- W3C DCAT version 3 (2024)
- Croissant dataset metadata (2024)
- Datasheets for Datasets (2021)
- Model Cards for Model Reporting (2019)
Provenance, citation, and retraction
- W3C PROV-O (2013)
- CRediT contributor roles taxonomy (2022)
- ICMJE and COPE on AI and authorship (2023)
- NISO CREC (RP-45-2024)
- Crossref and the Retraction Watch database (2023)
- Fabricated citations from LLMs (Walters & Wilder 2023)
- AI tools cite retracted papers (MIT Technology Review 2025)
Governance and risk frameworks
- NIST AI Risk Management Framework (2023, 2024)
- EU AI Act (2024)
- OECD AI Principles (2024)
- ISO/IEC 42001:2023
- OpenAI, Practices for Governing Agentic AI Systems (2023)
- Chan et al., Visibility into AI Agents (2024)
- Kolt, Governing AI Agents (2025)
- JRC, The Role of AI in Scientific Research (2025)
- DeepMind, An Approach to Technical AGI Safety (2025)
Interface security and channels
- OWASP Top 10 for LLM Applications 2025
- OWASP MCP Top 10
- Invariant Labs, MCP tool poisoning (2025)
- Official MCP Registry (2025)
- IETF AIPREF vocabulary (draft)
- COAR survey on AI bots and crawlers (2025)
- Web-scraping AI bots disrupt scientific databases (Nature news, 2025)
Agent-tool design
- Anthropic, Writing effective tools for agents (2025)
- Anthropic, Code execution with MCP (2025)
- Anthropic, Advanced tool use (2025)
- Model Context Protocol specification
Human oversight
Evaluation
- REFORMS reporting standards (2024)
- NeurIPS Paper Checklist
- DOME recommendations for ML validation in biology (2021)
- Open and Sustainable AI in the life sciences (OSAI, 2025)
Dual-use and frontier safety
- METR, Common Elements of Frontier AI Safety Policies (2025)
- Frontier Model Forum, Components of Frontier AI Safety Frameworks
- Urbina et al., Dual use of AI-powered drug discovery (2022)
- Wittmann et al., Nucleic-acid biosecurity screening (2025)
- UK AI Security Institute, Frontier AI Trends (2025)
- Autonomous agent breach of Hugging Face (2026)
- US policy for oversight of Dual Use Research of Concern (2024)
Research ethics and data protection