Rules in, answers out
A calculator, a tax form. Every step was written by a person.
Learn AI From zero, for everyone
Eight short stops. Each one is a single idea and something to play with. Fifteen minutes, or jump to the stop you need. Know the basics already? Go to what an agent is and why it needs guardrails.
01 The basics
Classic software follows rules someone wrote. Generative AI learned patterns from a huge pile of examples, and now makes new things that fit them.
Three kinds of software: rules give the same output for the same input, machine learning sorts and scores from examples, generative AI makes new text, images and code.
A calculator, a tax form. Every step was written by a person.
A spam filter. It found its own rules in millions of examples. It sorts, it does not create.
An email, a picture, a piece of code. Claude, ChatGPT and Gemini are generative AI for text.
02 Under the hood
A language model does one thing: look at the text so far and guess the next piece. Everything impressive is that step, repeated very fast.
Press Run and watch the loop.
A sentence is cut into tokens, the tokens go into the model, the model picks the next token from a few candidates with probabilities, adds it to the text, and repeats.
The model read a huge amount of text and practised one exercise billions of times: guess the next piece, check, adjust.
Pieces of text, about three quarters of a word. Limits and prices are counted in them.
Using the trained model. Text in, next token out, repeat until the answer is done.
Everything the model can see at once. Fixed size. Outside it, nothing exists.
Drag to orbit. Hover a node.
Layers of nodes connected by lines; a signal lights up one layer after the other, from input to output.
Likely is not the same as true. An invented fact or command is a hallucination.
Picking the next token involves a little chance. Temperature sets how much.
A new conversation starts empty. Any memory is text that was saved and put back.
Clear request and the right files beat clever tricks. Noise in the context makes answers worse.
03 The program around the model
A model alone only returns text. The harness is the software around it that runs tools, keeps the conversation and checks the rules.
Pick an action. The model only writes a request; the gate decides.
.claude/settings.json.A request leaves the model and reaches a permission gate, which lets it through (allow), waits for you (ask) or bounces it back (deny) before it can touch your files.
Sends your request to the model, carries out its step, sends the result back. Repeat.
Read, edit, search, run commands, fetch pages. The model names a tool; the harness runs it.
Before each action: go, ask the human, or refuse. The only place a "no" can be enforced.
Chooses what the model sees, and summarises old parts when the window fills.
04 The kinds
Same model, very different reach. The further right, the more of your world it can touch.
Five kinds, by reach: a chat app touches nothing on your computer; an editor agent sees the open project; a terminal agent can do anything a command in that folder could; a cloud agent works on a copy of your repository on the vendor's machines; an SDK lets you build an agent with the tools you choose.
05 One harness, up close
Anthropic's harness for the Claude models: "an agentic coding tool that reads your codebase, edits files, runs commands". You describe the task; it works on your real project.
Claude Code runs in the terminal, in editors, as a desktop app and in the browser, all on the same engine with the same instruction files and settings.
Reads what it needs, changes things, checks the result. Repeat. You can interrupt any time.
Every file in the folder and every command you could run there. That reach is why rules and locks exist.
cd my-project, then claudeAsk "what does this project do?". Then /init writes a first CLAUDE.md. Install steps in the overview.
You: the signup form accepts empty emails. write a failing test, then fix it. Claude: wants to edit signup.test.ts ← asks first in Manual mode You: yes Claude: tests: 1 failing → edits signup.ts → tests: all passing
Your project's instructions, read at the start of every session. Guidance, not enforcement.
A SKILL.md under .claude/skills/: know-how or a workflow, loaded only when relevant.
Its own loop, its own context, reports back a summary. Keeps research out of your conversation.
Your script, run at fixed moments, every time, whatever the model decides. This is enforcement.
An open standard for plugging in a database, a tracker, a browser. Each one adds reach.
Skills, hooks, subagents and MCP servers in one install. Read what is inside first.
06 Practical
Most of them follow from one fact: the context window fills up fast, and quality drops as it fills.
Fill the window. When it is full, the harness compacts.
A box fills with blocks for messages, files and command output; when it is full the oldest blocks are squashed into one summary block, and the instruction file at the bottom always stays.
Tests, a build, a screenshot. Otherwise you are the tester.
Shift+Tab for plan mode. Skip it only for one-sentence changes.
The file, the symptom, and what "fixed" looks like.
Under 200 lines. Cut any line that prevents no mistake.
What must never happen goes in a deny rule or a hook.
/clear. After two failed corrections, clear and ask again.
Esc stops it. Esc Esc or /rewind goes back.
Checkpoints cover its file edits only, never a database.
Hundreds of file reads stay out of your conversation.
Deny rules hold in every mode. Bypass only in a container.
| You type | What happens |
|---|---|
/init | Writes a starter CLAUDE.md from your project. |
/context | Shows what is using space in the context window. |
/clear | Empties the context. Use it between unrelated tasks. |
/compact | Summarises the conversation to free space. |
/rewind | Restores an earlier conversation and code state. |
/permissions | Pre-approves the tools you trust. |
/model | Switches the Claude model mid-session. |
Shift+Tab | Cycles the permission mode, including plan mode. |
claude --continue | Picks up the last conversation in this folder. |
claude -p "…" | One request, no interactive screen. For scripts. |
Sources: Best practices, CLAUDE.md, Permission modes, Extend Claude Code, read on 5 October 2026. When this page and the docs disagree, the docs are right.
07 The neighbours
Every tool reads an instruction file and has a place where approvals are set. Only the names change.
| Tool | Where it runs | Instruction file it reads | Where approvals are set |
|---|---|---|---|
| Claude Code | Terminal, editor extensions, desktop app, browser | CLAUDE.md. An AGENTS.md is read by default only when there is no CLAUDE.md. |
Permission modes, plus deny, ask and allow rules in .claude/settings.json |
| Codex | CLI, IDE extension, cloud | AGENTS.md, from your home folder and from the Git root down |
Approval policy and sandbox modes. Network access is off by default. |
| Gemini CLI | Terminal | GEMINI.md by default. One setting makes it read AGENTS.md. |
Approval modes, deny rules in its policy engine, and a sandbox that is off by default |
| Cursor | Its own code editor | AGENTS.md, in the project root and in subfolders |
Run Mode (Auto-review or Allowlist), file protections, and a sandbox for commands |
| GitHub Copilot | VS Code, and a cloud agent | AGENTS.md |
Terminal auto-approve rules in VS Code. A repository firewall for the cloud agent. |
08 Vocabulary
Short, honest definitions. Search, or pick a group.
No term matches that. Try a shorter word.
CLAUDE.md for Claude Code, AGENTS.md for most other tools.The safety terms are explained with examples on the agents page.
About two minutes. Nothing leaves your browser. Next read: what an agent is and why it needs guardrails. Official docs under external sources.