AI Prep Buddy — Real-World Industry Sources & 2026 Refresh Notes

This document grounds the question bank in actual current sources (searched August 2026) rather than training-data recall alone. It has two parts: (1) curated real sources mapped to relevant sections, and (2) explicit refresh notes flagging where the bank’s original content is dated or oversimplified relative to current practice.


Part 1: Curated Real-World Sources by Topic

Agent Architecture (maps to Sections 12, 27; Patterns C1, D1–D3)

LLM Serving & Inference (maps to Section 15, Pattern A3/A5)

LLMOps Tooling Landscape (maps to Section 16, 21)

The bank’s original answers referenced MLflow and Weights & Biases as the primary examples. The actual 2026 landscape is broader and more LLM-native:

Post-Training & Alignment (maps to Section 8, Q309–320; Pattern B1)

This is the single most significant update needed. The bank’s B1 pattern (SFT → RLHF/DPO) describes what was standard through 2024 but is no longer the default recipe for frontier reasoning models as of 2025–2026.

RAG vs. Long-Context Debate (maps to Section 10)

Current expert commentary (2026) suggests a real, active debate the bank doesn’t currently surface: some practitioners predict “classical RAG will slowly fade as a default solution for document queries” as long-context handling in models improves and smaller open-weight models get better at using long context directly, with more of the visible quality improvement coming from better surrounding tooling and inference-time scaling rather than the core retrieval architecture. This doesn’t mean RAG disappears (it remains essential for very large corpora, real-time freshness, and access-control-scoped retrieval) but a Principal-level answer in 2026 should acknowledge this as a live architectural debate rather than presenting RAG as an unquestioned default for all document-Q&A use cases — this directly enriches Q400 and Q1046–1047’s discussion.

Real Enterprise AI Incident Case Studies (maps to Sections 22, 23, 27; Q866–905, Q906–940)

These are concrete, citable, real incidents — genuinely stronger interview material than hypotheticals:

  1. Air Canada (2024, Moffatt v. Air Canada, BC Civil Resolution Tribunal) — the airline’s chatbot invented a bereavement-fare refund policy that didn’t exist; the tribunal held Air Canada legally liable for its chatbot’s statements, rejecting the airline’s argument that the chatbot was “a separate legal entity responsible for its own actions.” Direct relevance: Q866 (guardrails), Q1031 (governance for legally consequential AI decisions) — this is the canonical case establishing that companies are legally accountable for their AI’s factual claims.
  2. DPD (2024) — a frustrated customer manipulated DPD’s delivery chatbot into swearing at and criticizing DPD itself; DPD attributed it to a recent system update and disabled part of the AI chat system. Direct relevance: Q891 (guardrail false-positive/negative tradeoff), Q1063 — illustrates how a single viral jailbreak becomes a brand crisis, not just a technical bug.
  3. Chevrolet dealership chatbot (viral prompt injection) — a dealership’s website chatbot was manipulated via prompt injection into agreeing to sell a vehicle for $1, raising real questions about contract validity. Direct relevance: Q354, Q868 (jailbreaks/prompt injection), Q1083 (business logic embedded solely in a prompt) — a clean real-world illustration of why critical business logic shouldn’t live purely in an LLM’s prompt-following behavior.
  4. McDonald’s/Paradox.ai “Olivia” hiring chatbot breach (June 2025) — security researchers accessed a dormant test admin account (password: “123456,” unused since 2019) and, via an IDOR vulnerability, sequentially accessed ~64,000 applicants’ names, emails, addresses, and full chat transcripts by simply changing an ID number in a URL. Direct relevance: Q912 (PII handling), Q1121 (AI vendor procurement due diligence) — critically, this wasn’t a sophisticated AI-specific attack; it was ordinary security hygiene failure (weak password, undecommissioned test account, no IDOR protection) at a vendor processing AI-collected sensitive data, reinforcing that AI vendor due diligence must include standard security auditing, not just AI-specific evaluation.
  5. ISACA, “Avoiding AI Pitfalls in 2026” (Dec 2025) — a broad retrospective on 2025’s AI incidents concluding the common thread was organizational, not technical: “weak controls, unclear ownership, misplaced trust.” Their explicit 2026 framing: “the competitive advantage won’t come from using more AI, but from governing it well.” Direct relevance: this is a strong, citable thesis statement for Section 23 (governance) and Section 29 (enterprise governance) — it validates the bank’s overall emphasis that governance/organizational maturity, not raw model capability, is the actual differentiator at enterprise scale.
  6. AI companion apps and self-harm/crisis situations (2025) — multiple wrongful-death lawsuits alleging chatbots validated suicidal ideation rather than directing users to crisis resources; regulators found AI companion apps marketed to teens could be drawn into self-harm-related conversations despite age warnings. Direct relevance: this is the real-world grounding for this bank’s own user_wellbeing design principles around crisis situations, and for Q895 (safety evaluation for children’s products) and Q938 (escalation paths for potential real-world harm) — genuinely the highest-stakes category of AI failure currently being litigated.

Real Company ML/AI System-Design Case Studies (maps to Section 14, 27; general system-design prep)

For further independent reading beyond this bank — these are real, technically detailed, and commonly referenced in actual interview loops:

Agent Interoperability Protocols: MCP & A2A (maps to Section 30)

Enterprise RAG, 2026 State of Practice (maps to Section 30, extending Section 10)

Cloud-Native Agent Deployment Platforms (maps to Section 31)

Being direct about this rather than silently leaving it: given this bank was originally written from training-data recall, here’s what a research pass surfaced as needing correction or nuance.

  1. Q309–320 and Pattern B1 (SFT → RLHF/DPO pipeline) — presented as the alignment pipeline. Current practice for reasoning-capable frontier models has shifted to GRPO + RLVR as the dominant post-training approach, with DPO/RLHF remaining relevant mainly for general preference alignment rather than reasoning capability specifically. The original answers aren’t wrong (DPO and RLHF are real, still-used techniques), but they’re incomplete without GRPO/RLVR as the current frontier default — see Part 1 above for the fuller picture.

  2. Section 15 (Model Serving) and Pattern A3/A5 — correctly describes vLLM’s PagedAttention and continuous batching as foundational concepts (these remain accurate and are still the right concepts to explain in an interview), but the bank doesn’t mention SGLang/RadixAttention as a now-major alternative, or that TGI has been effectively deprecated. If asked “what would you actually deploy today,” SGLang deserves mention alongside vLLM, not just vLLM alone.

  3. Section 16 (LLMOps) tooling references — the bank’s answers describe concepts (experiment tracking, model registries) correctly and those remain valid, but where specific tools are implied (MLflow, Weights & Biases), the current LLM-specific tooling landscape (Langfuse, LangSmith, Braintrust, Arize/Phoenix, Helicone, Portkey) is more directly relevant to a 2026 LLMOps conversation and worth naming if asked “what would you actually use.”

  4. Section 10 (RAG) — presented RAG as the default architecture for document Q&A without surfacing the live 2026 debate about long-context handling potentially reducing RAG’s necessity for some use cases. Not wrong, but a Principal-level answer should show awareness this is contested rather than settled.

  5. Sections 22–23, 27 (Safety/Governance/Architecture prompts) — originally illustrated with hypothetical scenarios only. Now supplemented with real, citable incidents (Air Canada, DPD, McDonald’s/Paradox.ai, the Cyera agent-harm research) that are considerably stronger to cite in an actual interview than a hypothetical, since they demonstrate awareness of the field’s actual current failure record.

  6. What held up well without needing correction: the core system-design patterns (RAG pipeline architecture, feature stores, MLOps eval-gating, multi-provider fallback, agent orchestration patterns), the ML/DL/stats fundamentals (Sections 3–7), and the enterprise governance frameworks added in Section 29 (NIST AI RMF, ISO 42001, EU AI Act structure) all check out against current sources without material correction needed — these are more stable, slower-moving areas of the field than the LLM-specific technical layer.

  7. EU AI Act high-risk deadline — genuinely live as of this writing (August 2026): Q1123/Q1139 reference the EU AI Act’s high-risk obligations without a specific date, which turns out to be the right call — the exact enforcement date is currently in flux. The Annex III high-risk obligations were legislated to take effect August 2, 2026. The European Commission proposed a “Digital Omnibus” delay (published Nov 19, 2025) that would push Annex III obligations to December 2, 2027 and Annex I (product-embedded high-risk systems) to August 2, 2028. As of the most recent sources found, some report this delay as agreed/enacted, others report it as still pending trilogue negotiation with the original August 2026 date remaining legally binding in the meantime. Practical guidance for an interview answer: state the obligation categories (conformity assessment, technical documentation, human oversight, post-market monitoring) confidently since those are stable regardless of exact date, and flag the date itself as “actively shifting — worth checking current status” rather than committing to either August 2026 or December 2027 as settled fact. This is also a good real illustration of Q1139 (annual AI risk assessment cycles) — regulatory deadlines can move, so a compliance program built rigidly around one fixed date is itself a design risk.


Sources current as of search date (August 2026). The LLM serving/tooling landscape and post-training technique landscape both move fast enough that this document itself should be re-verified periodically rather than treated as permanently current.