7.4 What to read next

Book 1 · Your Next Job TitleChapter 7 · section 4 of 8

This field is moving quickly and its vocabulary is not settled, so do not treat any current list of frameworks as a permanent map. Learn enough to compare systems by asking what they can see, what they can change, how they retain context, how they are evaluated, and who can stop them.

For practical starting points, read Anthropic’s Building Effective Agents, which makes a useful case for simple, composable patterns rather than unnecessary framework complexity.1 Read the OpenAI Agents SDK documentation for examples of tools, handoffs, sessions, guardrails, tracing, and human approval.2 Study the Model Context Protocol if you want to understand how agents connect to external tools and data — and study Microsoft’s Agent Control Specification if you want the closest open artifact to a portable permission envelope.34 Read the Agent Skills specification if you are about to encode a procedure you will reuse more than twice.5 Google’s Agent Development Kit and LangGraph are useful places to study more structured and stateful workflows; Temporal is the place to study durable waits and crash-safe history when a human approval may arrive hours later.67

For the wider picture, follow the Stanford AI Index, METR’s research on the length of tasks frontier models can complete, the NIST AI Risk Management Framework, and MIT Sloan’s reporting on the organizational work required to make agentic systems useful.891011 Read Tim O’Reilly’s “Why Open Source Matters for AI” if you want the architecture-of-participation argument in one place — Goose, Pi, open weights, MCP — before you lock your stack to a single appliance.12

A few books are worth putting on the shelf as well. Micheal Lanham’s AI Agents in Action is a hands-on introduction to building and connecting agents, and what it gives an orchestrator that this book does not is running code — an agent with memory, tools, and a feedback loop you can step through.13 Victor Dibia’s Designing Multi-Agent Systems concentrates on coordination patterns, evaluation, and agent experience, and it builds a small framework from scratch, which is the quickest cure for treating the frameworks in Chapter 5 as sealed boxes.14 Michael Albada’s Building Applications with AI Agents compares practical approaches to agent applications, and the comparison itself is the gift: one scenario across several frameworks under one evaluation harness, a discipline this book asks for and does not demonstrate.15 Sebastian Raschka’s Build a Large Language Model from Scratch is not about orchestration at all and remains one of the better ways to understand what sits underneath these systems; it shows you why Chapter 8’s variation is a property of sampling rather than a defect, by making you write the sampler.16 Valliappa Lakshmanan and Hannes Hapke’s Generative AI Design Patterns is the broader reference for retrieval, reliability, reasoning, and production concerns, and it supplies what a book about a role cannot: named patterns with working code and trade-offs for the problems you meet once the system is running.17

That is a long shelf, and nobody reads it in a week. If you read seven things before Monday, read these, in this order. I checked each in September 2026, and for each I have said what it does not cover, because that is where the work this book describes begins.

  1. Anthropic, “Building effective agents” (December 2024). Two engineers report what worked across dozens of customer deployments: simple, composable patterns — prompt chaining, routing, an evaluator-optimizer loop — with an autonomous agent loop added only when simpler designs fall short. Anthropic now flags its tooling as dated; the argument for starting simple has aged well. It says nothing about who holds authority over the system or who answers when it is wrong.
  2. OpenAI, “A practical guide to building agents” (April 2025). Thirty-four pages for product and engineering teams. Its durable contributions are the instruction to exhaust one agent’s capabilities before adding a second, and its two triggers for handing control to a person: a failure threshold crossed, or a high-risk action — cancelling orders, authorizing large refunds, making payments. A vendor document; it covers neither cost nor the organization around the agent.18
  3. Simon Willison, “The lethal trifecta for AI agents” (June 2025). One page, readable by anyone who has used email, and the single security idea a first-week orchestrator most needs: private data, untrusted content, and a way to send data out, in one system, is an exploitable system. His example is the one the manager in Section 13.7 needs — a tool that reads your mail is a tool an attacker can instruct by writing to you. It names the problem and one fix; the layered defense is Chapter 14’s.19
  4. OWASP, “Top 10 for Agentic Applications for 2026” (December 2025). The vocabulary your security team will use when they review what you built — goal hijack, agentic supply chain, memory poisoning — assembled by more than a hundred contributors. A risk list, not a design; it will not tell you what to build.20
  5. METR, “Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity” (July 2025), with its February 2026 update. Sixteen experienced developers, 246 real tasks, randomized: with AI tools they took 19 percent longer and believed they had been 20 percent faster. Read it for the gap between the feeling and the clock. Then read the update, in which METR calls its follow-up data unreliable because developers increasingly refused to work without AI, and says the 2025 result no longer reflects current tools. What survived both papers is the finding about self-report. Neither tells you what your uplift is; only your own measurement does.21
  6. Agent Skills, the specification. The format for the procedure you will write on Friday: a directory with a SKILL.md, YAML front matter with a name and a description, a Markdown body, and optional scripts and references loaded only when needed. Read it before you write the file, so the file is portable. Its allowed-tools field is marked experimental, and nothing in the format records who authorized what; it is a runbook standard, not a permission or audit standard.
  7. Andrej Karpathy, “Software Is Changing (Again)” (June 2025). A forty-minute talk to students, and the clearest statement of the design stance this chapter takes: partial-autonomy products with an autonomy slider and a fast generation-verification loop — “less Iron Man robots and more Iron Man suits,” because “this is the decade of agents” and “we need humans in the loop.” A talk about products and developers; the institution, the budget, and the question of who is accountable are not in it.22

None of that reading is a prerequisite for the week below. Read while you run it.


  1. Anthropic, “Building Effective Agents,” December 19, 2024, credited to “Erik S. and Barry Zhang,” https://www.anthropic.com/engineering/building-effective-agents. The article presents patterns Anthropic observed across “dozens of teams” — the augmented LLM, prompt chaining, routing, parallelization, orchestrator-workers, evaluator-optimizer, and the autonomous agent loop — and argues for simple, composable designs, adding agentic structure “only when simpler solutions fall short.” As of September 2026 the page carries Anthropic’s own notice that “much of the tooling landscape described in this post has changed since December 2024.” Guidance from a model company, not a universal standard; it does not address authority, accountability, or cost. Verified September 9, 2026.↩︎

  2. OpenAI, “Agents SDK,” documentation. https://openai.github.io/openai-agents-python/ and https://developers.openai.com/api/docs/guides/agents. These pages document the SDK’s capabilities; they do not establish that every workflow should use the SDK.↩︎

  3. Model Context Protocol, official documentation. https://modelcontextprotocol.io/. MCP defines an open protocol for connecting AI applications to external data sources and tools; it does not by itself provide governance or safety.↩︎

  4. Microsoft Agent Governance Toolkit — Agent Control Specification, https://github.com/microsoft/agent-governance-toolkit/blob/main/policy-engine/spec/SPECIFICATION.md. Closest open portable policy-envelope artifact at time of writing; early/beta relative to fleet-wide ownership needs.↩︎

  5. Agent Skills specification, https://agentskills.io/specification. Portable SKILL.md packaging for procedures; not a permission or audit standard.↩︎

  6. Google, Agent Development Kit documentation. https://google.github.io/adk-docs/. This is a product and framework documentation source, not an independent evaluation.↩︎

  7. LangChain, LangGraph documentation. https://langchain-ai.github.io/langgraph/. LangGraph documents stateful, graph-based agent workflows and human-in-the-loop patterns. Temporal’s AI solutions overview (https://temporal.io/solutions/ai) is a useful companion for durable execution and human-approval waits.↩︎

  8. Stanford Institute for Human-Centered Artificial Intelligence, AI Index Report. https://hai.stanford.edu/ai-index. The report tracks research, capability, adoption, and economic indicators; its measures do not provide a single forecast for the future of work.↩︎

  9. METR, research on AI task horizons and model task completion. https://metr.org/. METR’s results concern measured task performance under particular evaluation conditions; they are not a guarantee of reliable autonomous work in a business.↩︎

  10. National Institute of Standards and Technology, AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework. The framework offers voluntary risk-management guidance and is not a certification for orchestrators.↩︎

  11. MIT Sloan, “Agentic AI, explained.” https://mitsloan.mit.edu/ideas-made-to-matter/agentic-ai-explained. The article emphasizes the organizational, data, governance, and workflow work required beyond model capability.↩︎

  12. Tim O’Reilly, “Why Open Source Matters for AI,” O’Reilly Radar, August 2026, https://www.oreilly.com/radar/why-open-source-matters-for-ai/. Cited for the architecture of participation — modularity and exit options — not as a claim that open always wins the demo.↩︎

  13. Micheal Lanham, AI Agents in Action (Shelter Island, NY: Manning, February 2025), ISBN 9781633436343, https://www.manning.com/books/ai-agents-in-action. Manning lists a second edition in preparation as of September 2026. A builder’s book; it does not take up organizational authority or accountability, which is not its job.↩︎

  14. Victor Dibia, Designing Multi-Agent Systems: Principles, Patterns, and Implementation for AI Agents (self-published, November 2025), ISBN 979-8-9931012-0-0, https://multiagentbook.com/; code at https://github.com/victordibia/designing-multiagent-systems. Dibia is a Microsoft Research engineer and AutoGen maintainer. Self-published, so without a publisher’s editorial layer.↩︎

  15. Michael Albada, Building Applications with AI Agents: Designing and Implementing Multiagent Systems (Sebastopol, CA: O’Reilly Media, 2025), ISBN 9781098176495; O’Reilly’s catalog dates it September 2025, retail listings October 21, 2025. Companion code at https://github.com/michaelalbada/BuildingApplicationsWithAIAgents. A practitioner’s book, not an independent evaluation of the frameworks it compares.↩︎

  16. Sebastian Raschka, Build a Large Language Model (From Scratch) (Shelter Island, NY: Manning, September 2024), ISBN 9781633437166, https://www.manning.com/books/build-a-large-language-model-from-scratch. Builds a GPT-2-class model on a laptop; says nothing about agents or orchestration.↩︎

  17. Valliappa Lakshmanan and Hannes Hapke, Generative AI Design Patterns: Solutions to Common Challenges When Building GenAI Agents and Applications (Sebastopol, CA: O’Reilly Media, October 2025), ISBN 9798341622654; code at https://github.com/lakshmanok/generative-ai-design-patterns. A pattern catalog; it covers reliability and agentic composition, not governance or the role.↩︎

  18. OpenAI, A practical guide to building agents, 34 pp., https://cdn.openai.com/business-guides-and-resources/a-practical-guide-to-building-agents.pdf. The PDF is undated; contemporaneous coverage places its release in mid-April 2025. Cited for “maximize a single agent’s capabilities first” and the two intervention triggers — “exceeding failure thresholds” and “high-risk actions,” with the examples “canceling user orders, authorizing large refunds, or making payments.” A vendor guide oriented toward the OpenAI Agents SDK; it does not treat cost, organizational design, or accountability. Verified September 9, 2026.↩︎

  19. Simon Willison, “The lethal trifecta for AI agents: private data, untrusted content, and external communication,” June 16, 2025, https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/. The email example paraphrased in Section 13.7 reads: “Something as simple as a tool that can access your email? That’s a perfect source of untrusted content: an attacker can literally email your LLM and tell it what to do!” Chapter 14 cites the same post for the defensive stack. Verified September 9, 2026.↩︎

  20. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications for 2026,” December 9, 2025, https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (PDF: https://genai.owasp.org/download/52117), described by the project as developed “with more than 100 industry experts, researchers, and practitioners.” Chapter 14 cites the same document for its specific entries and limitations. Verified September 9, 2026.↩︎

  21. Joel Becker et al. (METR), “Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity,” arXiv:2507.09089, https://arxiv.org/abs/2507.09089: 16 developers completed 246 tasks 19 percent more slowly with AI while perceiving a speedup. METR’s 2026 follow-up called the original result outdated and new data unreliable, https://metr.org/blog/2026-02-24-uplift-update/. Cited for the perception gap, not current tool productivity.↩︎

  22. Andrej Karpathy, “Software Is Changing (Again),” keynote at Y Combinator’s AI Startup School, published June 19, 2025, https://www.ycombinator.com/library/MW-andrej-karpathy-software-is-changing-again (video: https://www.youtube.com/watch?v=LCEmiRjPEtQ). The transcript supports the quoted phrases and the “autonomy slider” and generation-verification framing. A talk about products and developer practice; it does not address institutions or accountability. Verified September 9, 2026.↩︎