Learn AI From zero, for everyone

Generative AI, from the first word to a working agent.

Eight short stops. Each one is a single idea and something to play with. Fifteen minutes, or jump to the stop you need. Know the basics already? Go to what an agent is and why it needs guardrails.

01 The basics

What generative AI is, and what it is not.

Classic software follows rules someone wrote. Generative AI learned patterns from a huge pile of examples, and now makes new things that fit them.

Left: rules, same in, same out. Middle: machine learning sorts. Right: generative AI makes.

Three kinds of software: rules give the same output for the same input, machine learning sorts and scores from examples, generative AI makes new text, images and code.

Classic software

Rules in, answers out

A calculator, a tax form. Every step was written by a person.

Machine learning

Examples in, a judgement out

A spam filter. It found its own rules in millions of examples. It sorts, it does not create.

Generative AI

A request in, something new out

An email, a picture, a piece of code. Claude, ChatGPT and Gemini are generative AI for text.

Three things it is not

Next: how a model answers

02 Under the hood

How a model answers: one small piece at a time.

A language model does one thing: look at the text so far and guess the next piece. Everything impressive is that step, repeated very fast.

Sentence:

Press Run and watch the loop.

A toy model. The bars are the candidates for the next token and how likely each is. A real model does this with billions of parameters.

A sentence is cut into tokens, the tokens go into the model, the model picks the next token from a few candidates with probabilities, adds it to the text, and repeats.

  1. Training

    The model read a huge amount of text and practised one exercise billions of times: guess the next piece, check, adjust.

  2. Tokens

    Pieces of text, about three quarters of a word. Limits and prices are counted in them.

  3. Inference

    Using the trained model. Text in, next token out, repeat until the answer is done.

  4. Context window

    Everything the model can see at once. Fixed size. Outside it, nothing exists.

Go deeper: the network inside a model, in 3D

Drag to orbit. Hover a node.

Nodes in layers, every node wired to the next layer. Training tunes the strength of each wire. Real models have billions of them.

Layers of nodes connected by lines; a signal lights up one layer after the other, from input to output.

What follows from that

Consequence 1

Fluent and wrong

Likely is not the same as true. An invented fact or command is a hallucination.

Consequence 2

Same question, different answers

Picking the next token involves a little chance. Temperature sets how much.

Consequence 3

It forgets between chats

A new conversation starts empty. Any memory is text that was saved and put back.

Consequence 4

Input decides output

Clear request and the right files beat clever tricks. Noise in the context makes answers worse.

Next: what a harness is

03 The program around the model

What a harness is: the part that gives the model hands.

A model alone only returns text. The harness is the software around it that runs tools, keeps the conversation and checks the rules.

The model wants to…

Pick an action. The model only writes a request; the gate decides.

The model never touches your files. Every request passes the gate: allow, ask you, or deny. This gate is what Agent Safeguard writes as .claude/settings.json.

A request leaves the model and reaches a permission gate, which lets it through (allow), waits for you (ask) or bounces it back (deny) before it can touch your files.

Job 1

Runs the loop

Sends your request to the model, carries out its step, sends the result back. Repeat.

Job 2

Provides the tools

Read, edit, search, run commands, fetch pages. The model names a tool; the harness runs it.

Job 3

Decides what is allowed

Before each action: go, ask the human, or refuse. The only place a "no" can be enforced.

Job 4

Manages the context

Chooses what the model sees, and summarises old parts when the window fills.

Next: the five kinds of harness

04 The kinds

Five kinds of harness, by how much they can reach.

Same model, very different reach. The further right, the more of your world it can touch.

Chat apps (Claude, ChatGPT, Gemini), editor agents (Cursor, Copilot), terminal agents (Claude Code, Codex CLI, Gemini CLI), cloud agents (Claude Code on the web, Codex Cloud), and SDKs to build your own.

Five kinds, by reach: a chat app touches nothing on your computer; an editor agent sees the open project; a terminal agent can do anything a command in that folder could; a cloud agent works on a copy of your repository on the vendor's machines; an SDK lets you build an agent with the tools you choose.

Next: Claude Code, up close

05 One harness, up close

Claude Code, in plain words.

Anthropic's harness for the Claude models: "an agentic coding tool that reads your codebase, edits files, runs commands". You describe the task; it works on your real project.

One engine, four places to use it. Your CLAUDE.md, settings and MCP servers work in all of them.

Claude Code runs in the terminal, in editors, as a desktop app and in the browser, all on the same engine with the same instruction files and settings.

How it works

Gather, act, verify

Reads what it needs, changes things, checks the result. Repeat. You can interrupt any time.

What it reaches

Your project and your terminal

Every file in the folder and every command you could run there. That reach is why rules and locks exist.

Getting started

cd my-project, then claude

Ask "what does this project do?". Then /init writes a first CLAUDE.md. Install steps in the overview.

You:     the signup form accepts empty emails.
         write a failing test, then fix it.
Claude:  wants to edit signup.test.ts   ← asks first in Manual mode
You:     yes
Claude:  tests: 1 failing → edits signup.ts → tests: all passing
Go deeper: the six pieces you can add to Claude Code
Always loaded

CLAUDE.md

Your project's instructions, read at the start of every session. Guidance, not enforcement.

Loaded when needed

Skills

A SKILL.md under .claude/skills/: know-how or a workflow, loaded only when relevant.

Separate worker

Subagents

Its own loop, its own context, reports back a summary. Keeps research out of your conversation.

Guaranteed

Hooks

Your script, run at fixed moments, every time, whatever the model decides. This is enforcement.

Outside connections

MCP servers

An open standard for plugging in a database, a tracker, a browser. Each one adds reach.

Bundle

Plugins

Skills, hooks, subagents and MCP servers in one install. Read what is inside first.

Next: ten habits for using it well

06 Practical

Using Claude Code well: ten habits.

Most of them follow from one fact: the context window fills up fast, and quality drops as it fills.

Fill the window. When it is full, the harness compacts.

A file costs four messages. Compaction squashes the oldest blocks into a summary. CLAUDE.md at the bottom is loaded again every session, so rules belong there.

A box fills with blocks for messages, files and command output; when it is full the oldest blocks are squashed into one summary block, and the instruction file at the bottom always stays.

  1. Give it a check it can run

    Tests, a build, a screenshot. Otherwise you are the tester.

  2. Plan before you build

    Shift+Tab for plan mode. Skip it only for one-sentence changes.

  3. Be specific

    The file, the symptom, and what "fixed" looks like.

  4. Keep CLAUDE.md short

    Under 200 lines. Cut any line that prevents no mistake.

  5. CLAUDE.md is a request

    What must never happen goes in a deny rule or a hook.

  6. Start fresh between tasks

    /clear. After two failed corrections, clear and ask again.

  7. Correct early

    Esc stops it. Esc Esc or /rewind goes back.

  8. Still commit to git

    Checkpoints cover its file edits only, never a database.

  9. Send research to a subagent

    Hundreds of file reads stay out of your conversation.

  10. Pick a permission mode on purpose

    Deny rules hold in every mode. Bypass only in a container.

Commands worth knowing
You typeWhat happens
/initWrites a starter CLAUDE.md from your project.
/contextShows what is using space in the context window.
/clearEmpties the context. Use it between unrelated tasks.
/compactSummarises the conversation to free space.
/rewindRestores an earlier conversation and code state.
/permissionsPre-approves the tools you trust.
/modelSwitches the Claude model mid-session.
Shift+TabCycles the permission mode, including plan mode.
claude --continuePicks up the last conversation in this folder.
claude -p "…"One request, no interactive screen. For scripts.

Sources: Best practices, CLAUDE.md, Permission modes, Extend Claude Code, read on 5 October 2026. When this page and the docs disagree, the docs are right.

Next: other harnesses side by side

07 The neighbours

Other harnesses, side by side.

Every tool reads an instruction file and has a place where approvals are set. Only the names change.

ToolWhere it runsInstruction file it readsWhere approvals are set
Claude Code Terminal, editor extensions, desktop app, browser CLAUDE.md. An AGENTS.md is read by default only when there is no CLAUDE.md. Permission modes, plus deny, ask and allow rules in .claude/settings.json
Codex CLI, IDE extension, cloud AGENTS.md, from your home folder and from the Git root down Approval policy and sandbox modes. Network access is off by default.
Gemini CLI Terminal GEMINI.md by default. One setting makes it read AGENTS.md. Approval modes, deny rules in its policy engine, and a sandbox that is off by default
Cursor Its own code editor AGENTS.md, in the project root and in subfolders Run Mode (Auto-review or Allowlist), file protections, and a sandbox for commands
GitHub Copilot VS Code, and a cloud agent AGENTS.md Terminal auto-approve rules in VS Code. A repository firewall for the cloud agent.

Next: all the jargon

08 Vocabulary

All the jargon, in one place.

Short, honest definitions. Search, or pick a group.

Models and training

Artificial intelligence (AI)
The broad name for software that does tasks we used to think needed human thinking. Everything below is a part of it.
Machine learning
Software that finds its own rules in examples, in place of rules written by a programmer.
Neural network
The structure most machine learning uses: layers of simple connected units, each with adjustable numbers.
Deep learning
Machine learning with neural networks that have many layers. The method behind today's AI.
Generative AI
AI that produces new text, images, sound or code, as opposed to only sorting or scoring.
Model
The trained result: one large file of numbers that turns an input into an output. Claude, GPT and Gemini are model families.
LLM, large language model
A model trained on text to predict the next token. It writes, summarises, translates and codes.
Foundation model
A large general-purpose model that many different products are built on.
Transformer
The neural network design nearly all LLMs use. It lets the model weigh every part of the text against every other part.
Parameters, weights
The numbers inside a model that were adjusted during training. Large models have billions of them.
Training
The one-time process of adjusting the parameters on a huge amount of data. Done by the model maker, not by you.
Training data
The text, images or code a model learned from. Its gaps and biases show up in the answers.
Fine-tuning
Extra training of a finished model on a smaller, specialised set of examples.
Knowledge cutoff
The date training data ends. The model knows nothing newer unless it is put into the context.
Multimodal
Able to handle more than one kind of input or output, such as text, images and audio.
Diffusion model
The kind of model behind most image and video generators. It starts from noise and refines it step by step.
Open-weight model
A model whose parameters are published, so anyone can download and run it on their own hardware.
Benchmark
A fixed set of tasks used to compare models. Useful, but a high score does not promise good results on your task.
AGI
Artificial general intelligence: a hoped-for or feared AI that matches people at most intellectual work. There is no agreed definition or test.

How a model answers

Token
A piece of text, roughly three quarters of a word. Models read, write and are billed in tokens.
Inference
Running a trained model to get an output. Every chat message is an inference.
Prompt
The text you give a model: your question or instruction, plus any material you attach.
System prompt
Instructions the product places in front of every conversation, before your first message.
Context window
Everything the model can see at once, measured in tokens. It has a hard limit.
Temperature
A setting for how much chance goes into picking each token. Low is steadier, high is more varied.
Hallucination
A confident, plausible, wrong answer: an invented fact, quote, command or library.
Reasoning, thinking
A mode where the model first writes out working steps for itself before the final answer. Slower, often better on hard problems.
Streaming
Showing the answer token by token as it is produced, so you do not wait for the whole reply.
Latency
How long you wait for a response. Bigger models and longer contexts are usually slower.
Embedding
A list of numbers that stands for the meaning of a piece of text, so that similar texts get similar numbers. Used for search.

Prompting and knowledge

Prompt engineering
Writing requests so the model does what you mean: clear goal, needed facts, examples, the format you want.
Context engineering
Deciding what goes into the context window and what stays out. For agents this matters more than wording.
Zero-shot, few-shot
Asking with no examples, or with a few examples of the answer you want. Examples usually help.
Chain of thought
Asking the model to work through a problem step by step before it answers.
RAG
Retrieval-augmented generation: first search your documents for relevant passages, then give them to the model with the question.
Vector database
A store for embeddings that finds the passages closest in meaning to a question. A common part of RAG.
Grounding
Tying an answer to sources supplied in the context, so it can be checked and is less likely to be invented.
Structured output
Making the model reply in a fixed format such as JSON, so another program can read the answer.

Agents and tools

Agent
A model plus a harness, working toward a goal by repeatedly thinking, acting through tools and looking at the result.
Agentic loop
The cycle an agent runs: gather context, take an action, check the result, repeat.
Harness
The program around the model that runs the loop, provides the tools, enforces permissions and manages the context.
Tool, tool call, function calling
One ability the harness offers the model, and one use of it. The model asks in text. The harness runs it.
MCP
Model Context Protocol: an open standard for connecting an agent to external tools and data. Each server you add is more reach.
Instruction file
A markdown file the agent reads at the start: CLAUDE.md for Claude Code, AGENTS.md for most other tools.
Skill
A packaged set of instructions or a workflow that the agent loads only when the task calls for it.
Subagent
An agent started by another agent for part of the job. It has its own context and returns a summary.
Multi-agent, orchestration
Several agents working on one job, with one of them or a script handing out the parts and collecting the results.
Hook
Your own script that the harness runs at a fixed moment, such as before a tool call. It runs every time, so it can enforce a rule.
Plugin
An installable bundle of skills, hooks, subagents and MCP servers.
Plan mode
A mode where the agent reads and proposes a plan but does not edit until you approve.
Compaction
Summarising older parts of a long conversation to free space in the context window. Early details can get lost.
Checkpoint
A saved snapshot of files before the agent edits them, so the change can be rewound. Not a replacement for git.
Memory
Notes saved between sessions and loaded back into the context. The model itself remembers nothing.
Headless, non-interactive mode
Running an agent from a script or a build pipeline with no person watching the screen.
Vibe coding
Building software by describing it to an agent and judging the result, without reading the code.

Safety and control

Guardrail
Any measure that keeps an AI system inside limits: a rule, a permission check, a filter, a sandbox.
Permission mode
A harness setting for how much it does without asking you first.
Deny, ask, allow rule
A permission rule the harness enforces: never run this, pause and ask me, or go ahead.
Sandbox
An operating-system boundary around commands: which folders they may write to and which websites they may reach.
Prompt injection
Text hidden in something the agent reads that tries to give it new instructions. The model cannot reliably tell it from yours.
Jailbreak
A prompt written to talk a model out of its built-in safety rules.
Data exfiltration
Data leaving where it should stay, for example an agent tricked into sending a secret key to a website.
Human in the loop
A design where a person approves certain actions before they run. Ask rules are the mechanical version.
Least privilege
Giving a program only the access its job needs, and nothing more.
Alignment
The work of making a model's behaviour match what its makers and users actually intend.
Evals
Repeatable tests of a model or an agent on tasks you care about. The AI version of a test suite.
Red teaming
Deliberately attacking your own AI system to find its weaknesses before someone else does.

Cost and operations

API
The way one program talks to another. Products reach a model through the model maker's API.
API key
A secret string that identifies you to an API and is billed to you. Treat it like a password. Never paste it into a chat.
Model provider
The company or cloud service that runs the model for you.
Input and output tokens
What you send and what the model writes. Both are billed, usually at different prices.
Prompt caching
Reusing an unchanged beginning of a prompt across requests, which makes them cheaper and faster.
Rate limit
A cap on how many requests or tokens you may use in a period of time.

The safety terms are explained with examples on the agents page.

Now give your agent house rules.

About two minutes. Nothing leaves your browser. Next read: what an agent is and why it needs guardrails. Official docs under external sources.

Generate my rules