Reading about GenAI failure modes is one thing. Attacking a real application and watching a control hold — or not — is another. A RAG assistant built five times, a multi-agent system that plans and books a trip over MCP, and a capital-markets capstone that answers the same derivatives questions three different ways. These are what you test on the course. Your trainer assigns the ones you can open.