Section21

Skills and Organizational Readiness

On-premises AI infrastructure is buildable and operable by one to a few dedicated practitioners over a one-to-three-year horizon, using online documentation, training, and open-source tooling that did not exist three years ago, with specialist contractors optionally engaged at each phase boundary. This is a capability roadmap that does not necessarily require the organization to immediately staff an entire team of machine learning engineers, data scientists, and AI infrastructure specialists.

The U.S. Small Business Administration (SBA) Office of Advocacy counts 36,207,130 small businesses, of which 82.3 percent have no employees at all and 17.7 percent, roughly 6.4 million firms, have paid employees [1]. Adoption is not waiting for headcount. Census Business Trends and Outlook Survey data compiled by the Office of Advocacy show that between September 2024 and August 2025, 7.6 percent of businesses used artificial intelligence. Firms with more than 250 employees led at 11.4 percent, followed immediately by firms with fewer than five employees at 8.2 percent; noting that the gap between the two has narrowed [1]. The smallest organizations are adopting at rates approaching the largest while commanding a fraction of the staff.

Concentration inside technical teams is measurable. In 2016, Avelino et al. estimated truck factors, a metric measuring the concentration of knowledge in software development environments identifying the number of developers a project can lose before it is incapacitated, across 133 popular GitHub systems: 45 systems (34 percent) had a truck factor of one, 42 systems (31 percent) had two, and 87 in total (65 percent) sat at two or below [2]. Their developer survey validates the underlying authorship model more strongly than it validates the estimates themselves. Surveying developers from 67 target systems, 84 percent of respondents agreed or partially agreed that the identified authors were their projects’ main developers, while only 53 percent gave a positive or partially positive answer about the truck-factor estimate; several arguing that open-source projects can recruit replacements [2]. Read conservatively, the finding still holds: knowledge concentration in small technical teams is a frequent condition. Resource availability, sequenced technical capability, determination, and security discipline determine whether the buildout safely reaches production; headcount does not.

The Capability Roadmap, Sequenced

The roadmap assumes a practitioner who is familiar with Linux system administration, Python, and running containers. Skill development follows the three-phase hardware roadmap in a specific order; giving the practitioner the necessary foundations to build on as deployment capabilities scale.

Inference serving comes first since that is the foundational capability every deployment depends on. The resources are vendor documentation and structured courses where available: the vLLM project documentation for the serving engine, and the NVIDIA GPU Operator documentation for the Kubernetes integration the server taxonomy sets as the Phase 1 baseline. In June of 2026, vLLM introduced an official hands-on course in partnership with RedHat and DeepLearning.ai, covering LLM fundamentals along with the optimize, deploy, and benchmark lifecycle using vLLM and its suite of tools [3]. NVIDIA doesn’t provide an official course specifically for the GPU Operator, but it is covered extensively throughout their Deep Learning Institute and online documentation. The Linux Foundation’s Introduction to AI/ML Toolkits with Kubeflow (LFS147) covers adjacent Kubernetes-native machine learning workflows, and the Certified Kubernetes Administrator credential supports the orchestration layer [4], [5], [6]. The specific vLLM-under-k3s deployment skill is learned by reading the project documentation, standing up a test instance, and working through deployment tasks. NVIDIA’s Deep Learning Institute self-paced course titled “Building RAG Agents with LLMs” covers the inference-serving-plus-retrieval pattern end to end [7], [8].

Prompt and context engineering with retrieval-augmented generation (RAG) pipeline construction comes second since the Phase 1 chatbot the investment thesis depends on needs both. Anthropic’s prompt engineering documentation is the canonical reference and now designates its prompting best-practices page as the living reference, with interactive tutorials alongside it [9]; the September 2025 post on context engineering extends the same discipline into the agentic patterns Phase 2 will need [10]. Hugging Face’s LLM course is free and covers the Transformers, Datasets, Tokenizers, and Accelerate toolchain that Phase 1 deployments standardize on [11]. For the pipeline side, the operative documentation is Apache Airflow’s MLOps guides, LlamaIndex, Unstructured.io, and whichever vector store the taxonomy’s conditional selects, pgvector where PostgreSQL is already in production and Qdrant where it is not [12], [13]. That specification is what makes the path actionable. Without the architecture decision already made, “learn RAG” has no concrete referent.

Agent development and orchestration comes third, enabling the Phase 2 agentic workflows. LangChain Academy is the maintained, free path, with courses on LangGraph, the Deep Agents harness, and observability through LangSmith [14]. NVIDIA added an Agentic AI professional exam (NCP-AAI, $200) to its 2026 portfolio, covering the construction and governance of multi-agent systems [15], [16]. The Model Context Protocol (MCP) skill that the agentic infrastructure section makes central now has both a course and a moving target. Hugging Face’s free MCP course, built in partnership with Anthropic, runs from fundamentals through a deployed production application [17]. The specification remains the authoritative reference with a significant update on July 28, 2026. Revision 2026-07-28 retired the initialize handshake and the protocol-level session in favor of a stateless core, replaced server-initiated elicitation and sampling with Multi Round-Trip Requests, moved method and tool names into HTTP headers for gateway routing, hardened authorization toward client metadata documents, and deprecated Roots, Sampling, Logging, and the legacy HTTP and Server-Sent Events transport under a twelve-month minimum window [18], [19]. Software development kits (SDKs) for TypeScript, Python, Go, and C# shipped with it [19]. Course material lags a revision of that size, which is the general argument for treating the specification as the primary text and any course as scaffolding.

The agentic infrastructure section defines the orchestration loop as the control logic that lets a model plan, act, observe, and revise. Building one requires learning about typed states that survive step boundaries, checkpointing that resumes execution from the node where it halted, conditional branching that routes on tool results, and interrupt points where a human approves an action before it runs. Those are state-management and failure-handling problems, which separates a working prototype from a supervisable and auditable production agent.

Three orchestration layers appear in this stack. Agent orchestration governs the plan-act-observe loop inside a single task. Workflow orchestration, the Apache Airflow directed acyclic graph (DAG) scheduling already covered during the retrieval stage, governs recurring pipeline work on a clock or a trigger [12]. Cluster scheduling, Kubernetes at Phase 1 and a batch queue alongside the Phase 2 training server, governs which process gets which GPU. A practitioner who reaches for Airflow to retry a failed agent step has picked the wrong layer. Designing for resumption after partial failure is the one skill that applies across all three, which is why the agentic infrastructure section stores orchestration state in CPU-side storage backed by PostgreSQL and the S3-compatible object store rather than in process memory.

Fine-tuning and model evaluation comes fourth when deploying the Phase 2 training server. The Hugging Face PEFT (Parameter-Efficient Fine-Tuning) library documentation is the primary resource for Low-Rank Adaptation (LoRA) and its quantized variant QLoRA, the techniques that the training server will run [20]. The Hugging Face LLM course introduces fine-tuning through the Trainer API early and returns to it at depth in later chapters covering LLM fine-tuning, dataset curation, and reasoning models [11]. Andrej Karpathy’s Neural Networks: Zero to Hero builds networks from first principles in Python through a working GPT implementation, which is the prerequisite for debugging fine-tuning behavior and reading evaluation results instead of guessing at them [21], [22]. Karpathy published the series in 2023 and joined Anthropic’s pre-training team in May 2026, which this paper discloses because it cites Anthropic documentation elsewhere in the same learning path [23]. fast.ai’s Practical Deep Learning for Coders belongs in the learning path as a foundation. Its current release is the 2022 edition covering computer vision, natural language processing, and tabular data instead of LLM fine-tuning [24]. Hugging Face positions that course as a recommended prerequisite to its own since it covers deep learning and machine learning foundations that are important when fine-tuning LLMs [11]. Model evaluation as a discrete skill, benchmarking against the organization’s own tasks rather than published leaderboards, has no single course, and the practitioner reports discussed in the productivity paradox section are the operative input alongside the Hugging Face Evaluate documentation.

Multi-node GPU cluster management comes last, at Phase 3, when multi-server deployment arrives. NVIDIA’s 2026 portfolio treats AI infrastructure as its own certification domain: NVIDIA-Certified Professional AI Infrastructure (NCP-AII, $400) for deploying, configuring, and validating AI infrastructure; AI Operations (NCP-AIO, $500) for monitoring, troubleshooting, and optimizing it; AI Networking (NCP-AIN, $400) for the fabric; and the associate-level AI Infrastructure and Operations exam (NCA-AIIO, $125) beneath them [15]. Certifying early is not advisable. NVIDIA certifications are valid for two years and require retaking the exam to renew. A practitioner who receives a certification for AI infrastructure, such as NCP-AII, during Phase 1 will recertify before the Phase 3 hardware it validates against is installed [15].

Security Competencies That Belong From Day One

Security is the one domain that does not follow the phased deployment sequence. Prompt injection, model supply-chain risk, and access control for inference endpoints become live the moment the first chatbot retrieves from an untrusted document or the first user receives an application programming interface (API) key during the Phase 1 deployment.

The starting point is the Open Worldwide Application Security Project (OWASP) Top 10 for LLM Applications 2026, released August 4, 2026, superseding the 2025 edition and changing its methodology [25], [26]. Earlier editions rested on a community vote of contributing practitioners; the 2026 edition checks that vote against research grounded in thousands of documented real-world AI security incidents [25].

Several changes have a direct impact on the deployment this paper specifies. Prompt Injection holds first place as LLM01:2026, with its scope widened to cover cross-modal attacks and injections that persist in memory or within a retrieval corpus instead of expiring with the session. This is precisely the exposure a Phase 1 retrieval-augmented generation (RAG) pipeline creates the moment it ingests documents the organization does not control. Excessive Agency climbed from sixth to third (LLM03:2026), providing insights into real-world cases where agentic deployments reached production. System Prompt Leakage was renamed and broadened into Hidden Context Exposure (LLM08:2026), which now reaches tool schemas, retrieved policy text, and developer instructions alongside the system prompt. A practitioner who treats hidden context as a security control is designing against current guidance. Vector and Embedding Weaknesses slipped from eighth to ninth (LLM09:2026) naming RAG-specific failures such as embedding poisoning and unauthorized vector-database access. Supply Chain moved down one place to LLM04:2026, listing the third-party model-provenance risk this paper’s security architecture section makes operational [25], [26].

Unbounded Consumption, rising from tenth to sixth (LLM06:2026) [25], should be interpreted differently on owned hardware. On rented infrastructure, that risk surfaces as an invoice somebody eventually reviews and has to pay for. On the on-premises inference infrastructure this paper specifies, it surfaces as GPU occupancy where a carefully crafted request that monopolizes batch slots denies service to every other user. Token-aware limits belong on the serving endpoint from Phase 1 for that reason.

A structural change in the 2026 edition saves the practitioner real assembly work. OWASP now maps its risks to external frameworks including NIST, MITRE ATLAS, MITRE CWE, and the OWASP Top 10 for Agentic Applications [25], so the crosswalk from an AI risk to a governance control no longer has to be built by hand.

The OWASP Top 10 for Agentic Applications 2026, published December 9, 2025 and developed under peer review with more than 100 industry contributors, covers what the LLM list addresses only in part [27]. Its entries carry Agentic Security Initiative/Item (ASI) designations, four of which describe failures with no counterpart in single-turn deployments: Tool Misuse and Exploitation (ASI02), Memory and Context Poisoning (ASI06), Cascading Failures (ASI08), and Human-Agent Trust Exploitation (ASI09). An agentic deployment needs both lists: Top 10 for LLM Applications and Top 10 for Agentic Applications. Because MCP servers are the integration layer between the agentic compute server and the rest of the organization’s systems, OWASP’s practical guide to secure MCP server development is the operational companion to that taxonomy [28].

The National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF) 1.0 sets the governance layer the OWASP technical controls operate within. Its Core, developed over eighteen months as a consensus document with more than 240 contributing organizations, runs on four key functions: Govern, Map, Measure, and Manage. [29]. NIST states that AI RMF 1.0 is currently being updated and a revised version is in progress [29], so anything built directly on the 1.0 text should be structured to absorb the update. The base framework is also not the document an LLM deployment is governed against. Use-case profiles are the mechanism by which the framework is applied to a specific setting or application. In July 2024, NIST published the Generative AI Profile (NIST AI 600-1) that identifies risks specific to generative systems and maps actions for them onto the four functions [30], [31]. Other profiles currently under development will provide the necessary security guidance for deployments this paper specifies.

In April 2026, NIST’s Information Technology Laboratory launched development of an AI RMF Trustworthy AI in Critical Infrastructure Profile spanning information technology (IT), operational technology (OT), and industrial control systems (ICS) [32]. The profile is intended to guide critical infrastructure (CI) operators toward specific risk management practices when they adopt AI-enabled capabilities and how to state their trustworthiness requirements to teams, developers, and supply chain partners across both AI and CI lifecycles [32]. That second clause is where a small organization is affected. Organizations working with customers that operate critical infrastructure should expect these requirements to arrive as contract language rather than as a standard it elects to adopt. As of August 2026, NIST is running an open Community of Interest with a mailing list and a Slack channel that circulate discussion drafts for feedback, open across sectors, organizational roles, and supply chain partners [32].

Practitioners are now able to obtain the necessary credentials for AI application security to support the deployment this paper specifies. The Global Information Assurance Certification (GIAC) AI Platform Security (GAIPS) credential, awarded by an ANAB-accredited ISO/IEC 17024 certification body and tested through hands-on virtual machine exercises rather than multiple choice alone, validates a practitioner’s ability to audit and secure generative AI applications and LLM development pipelines. Its published objectives are similar the deployment this paper describes: retrieval-augmented architectures and the security risks of vector databases and external knowledge sources, agentic systems including inter-agent communication, context management, and protocol-level security, model customization and alignment through fine-tuning, MLOps and MLSecOps practices, and deployment security across hosting environments [33]. Its aligned course is the SANS (SysAdmin, Audit, Network, and Security) SEC545: GenAI and LLM Application Security, five days instructor-led or thirty hours self-paced across twenty labs covering prompt injection, RAG and vector database defense, LangChain, MCP attacks and OAuth security, Airflow, and model serialization and signing, priced at $8,260 with the certification attempt sold separately [34]. On the governance side, ISACA’s Advanced in AI Security Management (AAISM) credential is gated behind an active Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) credential, which closes it to a practitioner who did not come up through security management [35]. Priced against a two-to-three-year infrastructure budget, that same $8,260 buys the external prompt-injection review argued for earlier in this section. Treat the OWASP and NIST documents as the standing obligation that keeps the security skill current, and buy the credential when a customer contract or a second practitioner justifies the cost.

When Consultants and Managed Services Earn Their Place

The market for AI infrastructure and managed service providers (MSPs) is highly dynamic and fragmented; however, key market leaders maintain sufficient operational stability to be effectively evaluated and contracted within standard procurement timelines. What the practitioner needs is the selection criteria and the relationship pattern.

The Phase 1 deployment is the highest-risk moment for misconfiguration and the lowest point on the practitioner’s learning curve, an asymmetry that argues for buying expertise. A managed service provider for initial GPU server configuration should show production experience with the NVIDIA GPU Operator on Kubernetes, a vLLM and TensorRT-LLM deployment history with reference customers willing to confirm it, and existing hardware-level relationships with NVIDIA, Dell, or Supermicro to match the vendor channel the phased hardware deployment roadmap establishes. The engagement must mandate knowledge transfer to the internal practitioner and/or team within a specified timeframe. Dell Technologies Professional Services, Supermicro’s authorized partner network, and NVIDIA’s Partner Network are the most procurement-aligned starting points [36], [37], [38], [39].

Preparing for the first fine-tuning run is the second moment to reach out for external expertise. A specialist with documented experience in fine-tuning tools such as Hugging Face Accelerate, DeepSpeed, Unsloth, MLflow integration, and the LoRA and QLoRA techniques can save weeks of troubleshooting a faulty configuration. This is a smaller and more specialized market than general GPU-infrastructure MSPs. Hugging Face sells direct engineering access through its Expert Support offering, which pairs Enterprise Hub subscribers with the maintainers of the training libraries themselves [40]. The NVIDIA Partner Locator filters the NVIDIA Partner Network by country, competency, and partner type, and the Professional Services and Advanced Technology categories identify firms that NVIDIA has validated for model development rather than hardware resale [38], [41]. The AWS Marketplace professional services catalog lists fixed-scope fine-tuning and MLOps engagements that an organization can contract under an existing cloud agreement, which shortens procurement for teams that already buy through that channel [42].

Before any agentic system with tool access reaches production, commission an external review of prompt-injection exposure. The Excessive Agency category and the production incidents the agentic infrastructure section documents, including CVE-2025-53773 in GitHub Copilot at a Common Vulnerability Scoring System (CVSS) base score of 7.8 (High), make this a category-level risk where independent peer review pays for itself even when the implementation is correct.

Ongoing operations invert the initial-configuration logic. Build internal capability for daily operations and keep two or three specialist relationships warm through periodic engagement: annual configuration reviews, occasional troubleshooting, and post-incident review, so there is a quick response when something critical breaks. The failure mode runs the other way, outsourcing daily operations to an MSP and then trying to learn the work in-house only when a crisis forces it.

The Key-Person Dependency Problem

The roadmap concentrates expertise in one-to-few practitioners, which matches the frequently common scenario within most organizations. The prevalence evidence in the opening of this section establishes that the condition is the norm at this scale [1], [2]. Four protections form a mitigation strategy starting point to protect the project from failure against the key-person dependency problem.

Detailed documentation that is easy to find and comprehend provides the best form of protection. When Avelino et al. asked developers of high-concentration projects which practices most attenuate the loss of the authors who carry a system, documentation drew 36 mentions, more than twice the next answer, an active community at 15, followed by automated tests and code legibility at 10 each [2]. That ordering comes from practitioners who had already lived the exposure. The targets are the artifacts whose loss would hurt most: version-controlled deployment configurations in Git, model-evaluation records in MLflow, operational runbooks for inference-server health checks and restart procedures, and fine-tuning configurations paired with their evaluation outcomes. These coincide with the Phase 1 deliverables the server taxonomy specifies. Document as the work happens and details are fresh in memory; retroactive documentation usually never gets written.

Contractor relationships provide a second layer of protection. Keep two or three specialists engaged across the relevant profiles: a specialist for infrastructure incidents, a specialist for training-pipeline failures, and a specialist for AI security reviews. Annual engagements help keep the relationship healthy. Crisis-only contacts will more than likely result in slow response time when incidents occur.

Managed services for the highest-risk project milestones provide an additional layer of protection. This follows the same consulting guidance already mentioned. MSPs help mitigate risk at the first GPU server configuration and the first fine-tuning run where the gap between internal and external expertise is at its widest.

Staffing additional practitioners during Phase 1 and 2 development is the final recommended protection. Insert the case for additional AI practitioners within the Phase 1 plan, so the move from one-to-few practitioners to a small team is anticipated from the start. No published research proposes an optimal headcount for AI infrastructure teams within small and medium sized organizations. A single point of failure on infrastructure the organization has committed six-to-seven figures into over multiple years is a resilience cost of the investment thesis. Surfacing it in Phase 1 is recommended to prevent the challenges that come with it if introduced later on in Phase 2.

What This Roadmap Buys

The result is an organization that can implement, audit, and maintain its own AI capabilities instead of renting them by the hour. A practitioner who finishes the sequence operates the Phase 1 and Phase 2 stack under human-in-the-loop guidelines and reviews it against the OWASP frameworks, which is the difference between owning the security architecture and delegating it. That self-sufficiency compounds: every documented runbook, every versioned fine-tune, and every reviewed agent widens what a single practitioner or small team can safely operate before additional hires arrive. The skills required to build the Phase 1 and 2 capabilities can be learned on the timeline and budget this paper specifies with sequencing and discipline being the binding constraint.

References

  1. U.S. Small Business Administration, Office of Advocacy, “Frequently Asked Questions About Small Business,” Feb. 2026. [Online]. Available: https://advocacy.sba.gov/wp-content/uploads/2026/02/FINAL_FAQsAboutSmallBusiness_2026_012826.pdf. Original data: Census Bureau Statistics of U.S. Businesses 2022, Nonemployer Statistics 2022, and Business Trends and Outlook Survey. [Accessed: 29-Jul-2026]

    SKLS-1 Primary source Back to text

  2. G. Avelino, L. Passos, A. Hora, and M. T. Valente, “A Novel Approach for Estimating Truck Factors,” Proc. IEEE 24th Int. Conf. on Program Comprehension (ICPC), May 2016. [Online]. Available: https://arxiv.org/abs/1604.06766. Austin, TX, USA, pp. 1–10. doi:10.1109/ICPC.2016.7503718. [Accessed: 29-Jul-2026]

    SKLS-2 Primary source Back to text

  3. C. Clyburn, “Fast & Efficient LLM Inference with vLLM: A New Course with DeepLearning.AI,” vLLM Blog, vLLM Project, June 3, 2026. [Online]. Available: https://vllm.ai/blog/2026-06-03-deeplearning-ai-vllm-course. [Accessed: 31-Jul-2026]

    SKLS-3 Secondary source Back to text

  4. Linux Foundation Training & Certification, “AI & ML Course Catalog,” The Linux Foundation. [Online]. Available: https://training.linuxfoundation.org/ai-machine-learning/. [Accessed: 29-Jul-2026]

    SKLS-4 Primary source Back to text

  5. Linux Foundation Training & Certification, “Introduction to AI/ML Toolkits with Kubeflow (LFS147),” The Linux Foundation. [Online]. Available: https://training.linuxfoundation.org/training/introduction-to-ai-ml-toolkits-with-kubeflow-lfs147/. [Accessed: 29-Jul-2026]

    SKLS-5 Primary source Back to text

  6. Linux Foundation Training & Certification, “Certified Kubernetes Administrator (CKA),” The Linux Foundation. [Online]. Available: https://training.linuxfoundation.org/certification/certified-kubernetes-administrator-cka/. [Accessed: 29-Jul-2026]

    SKLS-6 Primary source Back to text

  7. NVIDIA Corporation, “Deep Learning Institute: Training and Certification.” [Online]. Available: https://www.nvidia.com/en-us/training/. [Accessed: 29-Jul-2026]

    SKLS-7 Primary source Back to text

  8. NVIDIA Corporation, “Building RAG Agents with LLMs (Self-Paced Course),” NVIDIA Deep Learning Institute. [Online]. Available: https://learn.nvidia.com/courses/course-detail?course_id=course-v1:DLI+S-FX-15+V1. [Accessed: 29-Jul-2026]

    SKLS-8 Primary source Back to text

  9. Anthropic, “Prompt Engineering Overview,” Claude Platform Docs. [Online]. Available: https://platform.claude.com/docs/en/build-with-claude/prompt-engineering/overview. Previously published under docs.anthropic.com, which now redirects to this URL. [Accessed: 29-Jul-2026]

    SKLS-9 Primary source Back to text

  10. Anthropic Applied AI Team, “Effective Context Engineering for AI Agents,” Anthropic Engineering Blog, Sept. 29, 2025. [Online]. Available: https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents. [Accessed: 28-Jun-2026]

    SKLS-10 Secondary source Back to text

  11. Hugging Face, “LLM Course,” Hugging Face, Inc.. [Online]. Available: https://huggingface.co/learn/llm-course. [Accessed: 29-Jul-2026]

    SKLS-11 Primary source Back to text

  12. Apache Software Foundation, “MLOps with Apache Airflow.” [Online]. Available: https://airflow.apache.org/use-cases/mlops/. [Accessed: 28-Jun-2026]

    SKLS-12 Primary source Back to text

  13. Qdrant, “Qdrant Documentation.” [Online]. Available: https://qdrant.tech/documentation/. [Accessed: 28-Jun-2026]

    SKLS-13 Primary source Back to text

  14. LangChain, “LangChain Academy: Course Catalog,” LangChain, Inc.. [Online]. Available: https://academy.langchain.com/. [Accessed: 29-Jul-2026]

    SKLS-14 Primary source Back to text

  15. NVIDIA Corporation, “Certification Programs,” June 23, 2026. [Online]. Available: https://www.nvidia.com/en-us/learn/certification/. 2026 portfolio, including NCP-AII, NCP-AIO, NCP-AIN, NCA-AIIO, and NCP-AAI; exam pricing and two-year certification validity. Updated Jun. 23, 2026. [Accessed: 29-Jul-2026]

    SKLS-15 Primary source Back to text

  16. NVIDIA Corporation, “Agentic AI LLMs Certification for Professionals (NCP-AAI),” May 25, 2026. [Online]. Available: https://www.nvidia.com/en-us/learn/certification/agentic-ai-professional/. [Accessed: 29-Jul-2026]

    SKLS-16 Primary source Back to text

  17. Hugging Face, “MCP Course,” Hugging Face, Inc.. [Online]. Available: https://huggingface.co/learn/mcp-course/unit0/introduction. Built in partnership with Anthropic. [Accessed: 29-Jul-2026]

    SKLS-17 Primary source Back to text

  18. Model Context Protocol, “Specification, Version 2026-07-28,” Model Context Protocol, a Series of LF Projects, LLC, July 28, 2026. [Online]. Available: https://modelcontextprotocol.io/specification/2026-07-28. [Accessed: 29-Jul-2026]

    SKLS-18 Primary source Back to text

  19. D. Soria Parra and D. Delimarsky, “The 2026-07-28 Specification,” Model Context Protocol Blog, July 28, 2026. [Online]. Available: https://blog.modelcontextprotocol.io/posts/2026-07-28/. [Accessed: 29-Jul-2026]

    SKLS-19 Secondary source Back to text

  20. Hugging Face, “PEFT: Parameter-Efficient Fine-Tuning Library,” Hugging Face, Inc.. [Online]. Available: https://huggingface.co/docs/peft. [Accessed: 28-Jun-2026]

    SKLS-20 Primary source Back to text

  21. A. Karpathy, “Neural Networks: Zero to Hero,” 2023. [Online]. Available: https://karpathy.ai/zero-to-hero.html. [Accessed: 28-Jun-2026]

    SKLS-21 Primary source Back to text

  22. A. Karpathy, “Neural Networks: Zero to Hero,” YouTube. [Online]. Available: https://www.youtube.com/playlist?list=PLAqhIrjkxbuWI23v9cThsA9GvCAUhRvKZ. Playlist, 10 videos. [Accessed: 28-Jun-2026]

    SKLS-22 Primary source Back to text

  23. TechCrunch, “OpenAI Co-Founder Andrej Karpathy Joins Anthropic's Pre-Training Team,” TechCrunch, May 19, 2026. [Online]. Available: https://techcrunch.com/2026/05/19/openai-co-founder-andrej-karpathy-joins-anthropics-pre-training-team/. [Accessed: 29-Jul-2026]

    SKLS-23 Contextual source Back to text

  24. J. Howard and S. Gugger, “Practical Deep Learning for Coders,” fast.ai, 2022. [Online]. Available: https://course.fast.ai/. 2022 edition. [Accessed: 29-Jul-2026]

    SKLS-24 Primary source Back to text

  25. OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2026,” OWASP Foundation, Aug. 3, 2026. [Online]. Available: https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/. OWASP Top 10 for LLM Applications 2026, v1.0, Aug. 4, 2026. [Accessed: 10-Aug-2026]

    SKLS-25 Primary source Back to text

  26. OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2025,” OWASP Foundation, Nov. 2024. [Online]. Available: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/. Superseded by the 2026 edition; kept as the baseline for the ranking changes. [Accessed: 10-Aug-2026]

    SKLS-26 Primary source Back to text

  27. OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications for 2026,” OWASP Foundation, Dec. 9, 2025. [Online]. Available: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/. [Accessed: 29-Jul-2026]

    SKLS-27 Primary source Back to text

  28. OWASP GenAI Security Project, “A Practical Guide for Secure MCP Server Development,” OWASP Foundation, Feb. 2026. [Online]. Available: https://genai.owasp.org/resource/a-practical-guide-for-secure-mcp-server-development/. [Accessed: 29-Jul-2026]

    SKLS-28 Primary source Back to text

  29. National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI Resource Center, U.S. Department of Commerce, Jan. 2023. [Online]. Available: https://airc.nist.gov/airmf-resources/airmf/. The AIRC landing page states a revised version is in progress as of August 2026. [Accessed: 10-Aug-2026]

    SKLS-29 Primary source Back to text

  30. National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework,” NIST AI RMF, U.S. Department of Commerce, 2024. [Online]. Available: https://www.nist.gov/itl/ai-risk-management-framework. [Accessed: 29-Jul-2026]

    SKLS-30 Primary source Back to text

  31. National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, National Institute of Standards and Technology, July 2024. [Online]. Available: https://doi.org/10.6028/NIST.AI.600-1. Gaithersburg, MD, USA. [Accessed: 29-Jul-2026]

    SKLS-31 Primary source Back to text

  32. National Institute of Standards and Technology, “Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure,” NIST Information Technology Laboratory, U.S. Department of Commerce, Apr. 6, 2026. [Online]. Available: https://www.nist.gov/programs-projects/concept-note-ai-rmf-profile-trustworthy-ai-critical-infrastructure. Updated Jul. 17, 2026. Project status: ongoing; staff: M. Stanley, R. Sheh. [Accessed: 10-Aug-2026]

    SKLS-32 Primary source Back to text

  33. Global Information Assurance Certification, “GIAC AI Platform Security (GAIPS),” GIAC, LLC, 2026. [Online]. Available: https://www.giac.org/certifications/ai-security-platform-security-gaips. [Accessed: 10-Aug-2026]

    SKLS-33 Primary source Back to text

  34. SANS Institute, “SEC545: GenAI and LLM Application Security,” The Escal Institute of Advanced Technologies, Inc., 2026. [Online]. Available: https://www.sans.org/cyber-security-courses/genai-llm-application-security. Course authored by A. AbuGharbia; 5 days instructor-led or 30 hours self-paced; 20 labs; 30 CPEs; $8,260 USD OnDemand and U.S. live events, excluding local taxes. [Accessed: 10-Aug-2026]

    SKLS-34 Primary source Back to text

  35. ISACA, “Advanced in AI Security Management (AAISM) Certification,” 2026. [Online]. Available: https://www.isaca.org/credentialing/aaism. [Accessed: 10-Aug-2026]

    SKLS-35 Primary source Back to text

  36. Dell Technologies, “AI Services,” Dell USA, 2026. [Online]. Available: https://www.dell.com/en-us/lp/dt/artificial-intelligence-services. [Accessed: 11-Aug-2026]

    SKLS-36 Primary source Back to text

  37. Super Micro Computer, Inc., “Where to Buy: Find an Authorized Partner.” [Online]. Available: https://www.supermicro.com/en/wheretobuy. [Accessed: 11-Aug-2026]

    SKLS-37 Primary source Back to text

  38. NVIDIA Corporation, “NVIDIA Partner Network (NPN),” 2026. [Online]. Available: https://www.nvidia.com/en-us/about-nvidia/partners/. [Accessed: 11-Aug-2026]

    SKLS-38 Primary source Back to text

  39. NVIDIA Corporation, “DGX-Ready Managed Services,” 2026. [Online]. Available: https://www.nvidia.com/en-us/data-center/dgx-ready-managed-services/. [Accessed: 11-Aug-2026]

    SKLS-39 Primary source Back to text

  40. Hugging Face, “Hugging Face Enterprise Support.” [Online]. Available: https://huggingface.co/support. [Accessed: 11-Aug-2026]

    SKLS-40 Primary source Back to text

  41. NVIDIA Corporation, “Find an NVIDIA Partner.” [Online]. Available: https://www.nvidia.com/en-us/about-nvidia/partners/partner-locator/. [Accessed: 11-Aug-2026]

    SKLS-41 Primary source Back to text

  42. Amazon Web Services, “Professional Services in AWS Marketplace.” [Online]. Available: https://aws.amazon.com/marketplace/features/professional-services. [Accessed: 11-Aug-2026]

    SKLS-42 Primary source Back to text

Contents