How-to guides
How to build, run, validate and govern AI you control
Each guide gives the short answer first, then numbered steps with copyable commands, what you should see, a troubleshooting table and a checklist to confirm it worked. Every guide carries the date its commands were last checked and the official sources used.
26 guides.
Build
Make a model, an agent, a knowledge layer or a retrieval system that runs on your own data.
How to Build a Company Brain for AI: A Practical Guide
Build a permission-aware knowledge layer for AI: resolve identities, copy access lists from each source, keep provenance, retrieve under access control, and test freshness and leaks.
- Intermediate
- Two to three days for one source and one team, then about a week per extra source
- 9 steps
How to Build a RAG System: Step-by-Step, Runs Locally
Build a retrieval-augmented generation system end to end on one machine, with hybrid search, per-group permissions, citations and a retrieval test set.
- Intermediate
- About 90 minutes to a working system, plus time to collect your own documents
- 9 steps
How to Build an AI Agent in 2026 (Code & No-Code)
Build an agent as a loop with tools, a turn budget and an eval set: define a narrow job, pick a build path, connect tools, choose models per step, test, deploy and observe.
- Intermediate
- About an afternoon for the loop; longer for the eval set
- 6 steps
How to Choose an LLM for Your Company: A Scorecard
A selection process, not a leaderboard: requirements, a hosted and open-weight shortlist, a test on your own tasks, a weighted scorecard, licence and data-terms checks, and an exit plan.
- Beginner
- About 2 to 5 working days, mostly collecting the test cases and reading terms. The test runs themselves take hours.
- 7 steps
How to Create Your Own Local Model: LoRA to GGUF
Adapt a small open-weight model to your own examples on one machine, convert it to GGUF, run it locally and check it beats the base model on cases it has not seen.
- Advanced
- About 1 day for a first working model: a few hours for data, then training time that depends on your hardware and example count.
- 9 steps
How to Fine-Tune an LLM on Your Own Data (2026)
The decision and the method: when fine-tuning beats prompting and retrieval, how to build and split the dataset, two training routes, how to evaluate, and what it really costs.
- Advanced
- About 1 to 2 weeks end to end, most of it on data and evaluation. The training run itself is usually the shortest part.
- 7 steps
Deploy
Run models on hardware and in regions you choose, from a laptop to an air-gapped site.
How to Build an Air-Gapped AI Environment (2026)
Stage model weights, container images and Python packages on a connected machine, verify and carry them across, run the model with every online lookup switched off, and prove nothing leaves.
- Advanced
- Allow one to two days for the first environment, mostly waiting on downloads, transfers and approvals. Later updates take a few hours.
- 8 steps
How to Deploy an LLM in the EU: Data Residency Steps
Choose between EU-region hosted APIs, a self-hosted open-weight model on EU infrastructure, or on-premises, then check storage, processing, logs, support access and sub-processors, and test where requests actually run.
- Intermediate
- About half a day to choose and configure a hosted EU option; one to two days to add a verification test and write the record. Self-hosting adds the time in the self-hosting guide.
- 7 steps
How to Run LLMs Locally: Ollama, LM Studio, llama.cpp
Install Ollama, LM Studio or llama.cpp, download a model that fits your memory, chat with it and call it from code through a local OpenAI-compatible endpoint.
- Beginner
- About 20 to 30 minutes, most of it downloading the model.
- 7 steps
How to Self-Host an LLM with vLLM (2026 Guide)
Serve an open-weight model as a private, OpenAI-compatible endpoint on your own GPU server, with memory sizing, authentication, TLS, metrics and an upgrade routine.
- Advanced
- About 2 to 3 hours for a first working endpoint; add a day for hardening, monitoring and a load test.
- 9 steps
How to Self-Host a ChatGPT Alternative (Open WebUI)
A hands-on setup of Open WebUI in front of a model you host, with admin accounts, roles, HTTPS, backups and a clear view of where prompts go.
- Intermediate
- About 1 to 2 hours for a working pilot, plus time for single sign-on and a short policy for users.
- 9 steps
Validate
Test whether a model or a system does the job before you rely on it, and keep testing.
How to Audit AI Systems: Scope, Evidence, Findings
How to audit an AI system, internally or for a client: scope it, choose criteria, request and sample evidence, test logs, change control and human oversight, and write findings that can be fixed.
- Intermediate
- Two to four weeks for one system, depending on how quickly evidence arrives
- 10 steps
How to Evaluate an Open-Source LLM: Hands-On Steps
Check the licence first, write a small task set of your own, run it against the full-precision and quantised model, add a public benchmark as a sanity check, measure speed and memory, and write down the decision.
- Intermediate
- About 4 hours for one candidate, plus the time to write your task set
- 9 steps
How to Validate Your AI: Eval Sets, Gates, Evidence
A system-level method to validate an AI product: define the task and risk, build a held-out eval set, score it, gate releases, sample for human review, monitor and keep an evidence pack.
- Intermediate
- One to two working days for the first suite; minutes per release after that
- 10 steps
Govern
Decide who and what may act, what needs a human, and how you will show it afterwards.
How to Detect Shadow AI in Your Organisation
Define what counts as unsanctioned AI, then find it through identity grants, network logs, expense data and a short staff survey, rank what you find by the data it touches, replace the risky tools with approved ones, and keep monitoring in a proportionate way.
- Intermediate
- About one to two weeks for a first sweep; then a monthly review
- 8 steps
How to Govern AI Agents: Identity, Policy, Approvals
Govern agents at runtime: list every agent, give each an identity and an owner, write down what it may and may not do in a Trust Profile, enforce allow, deny and approve rules, choose an autonomy level, record every action and review on a schedule.
- Intermediate
- About one week for the first inventory, profiles and policy on your main agents; then a standing monthly review
- 8 steps
How to Set Up Human Approval for AI Agents (With Code)
Decide which agent actions need a person, set thresholds, pause the agent with LangGraph interrupts, route requests to a queue with a timeout that denies by default, show reviewers the evidence, and record every decision.
- Intermediate
- About half a day for the design, one to two days to wire in and test
- 7 steps
Secure
Close the gaps that models, tools and agents open: injection, tool access, red-team testing.
How to Red Team an LLM App: Tools, Scoring, Retest
A step-by-step LLM red-team exercise: authorisation and scope, a threat model mapped to the OWASP LLM Top 10, automated testing with promptfoo, garak and PyRIT, manual attack sessions, scoring, fixes and retest.
- Advanced
- Two to five working days for a first exercise on one application
- 10 steps
How to Secure MCP Servers: OAuth, Scopes, Allow-Lists
Harden an MCP deployment against the attacks the specification names: validate token audience, never pass tokens through, ask for minimal scopes, sandbox local servers, allow-list servers, gate sensitive tools with a human, and log every call.
- Advanced
- About half a day to inventory and apply client-side controls; one to three days to harden a server you build
- 9 steps
How to Stop Prompt Injection: Layered Defences That Work
A layered defence for prompt injection: assume it will happen, keep untrusted content apart from instructions, give agents the fewest tools and shortest-lived privileges, require human approval for risky actions, block data leaving, and test with canary documents.
- Intermediate
- About one to two days to map and apply the controls to one application
- 8 steps
Comply
Work through the EU AI Act and data protection steps in the order a regulator would ask.
How to Do a DPIA for AI: GDPR Article 35 Steps
Decide whether an AI system needs a DPIA, then describe the processing, assess necessity, identify risks to people, choose measures, record the sign-off and review it, with AI-specific risks and a worked example.
- Intermediate
- Allow two to five working days for a first DPIA on a moderately complex system, spread over a few weeks for the consultations and sign-off.
- 7 steps
How to Prepare for the EU AI Act: 2026 Readiness Steps
A readiness workflow for the EU AI Act: inventory AI systems, rule out prohibited uses, set provider or deployer role, classify risk, plan obligations and evidence, and track the dates after the Digital Omnibus.
- Intermediate
- About one to two weeks for a first inventory and classification of a mid-sized organisation, longer if tools are bought across many teams. Evidence work continues after.
- 8 steps
Operate
Keep AI systems affordable, observable and routable once they are in production.
How to Migrate from OpenRouter or LiteLLM (Safely)
Inventory what you use, map model names, replay real requests against old and new routes, switch the base URL, then canary the traffic with a rollback ready.
- Intermediate
- About 1 to 2 days of work for one application, plus a canary period of a few days
- 9 steps
How to Monitor AI Agents in Production (2026 Guide)
Give every agent run an id, record each model and tool step as a span, redact before you store, alert on loops, tool failures and cost per run, and read a weekly sample by hand.
- Advanced
- About 4 hours for tracing, redaction and the first alerts; the weekly review is ongoing
- 8 steps
How to Reduce LLM Costs: Step-by-Step Guide (2026)
Measure token spend per feature first, then apply the levers in order of payoff: output caps, prompt caching, batch APIs, model routing, response caching, and a self-hosting break-even check.
- Intermediate
- About 3 hours to add measurement and the first three levers; routing and batch work take longer
- 8 steps
How to Set Up an LLM Gateway with LiteLLM (2026)
Run the open-source LiteLLM proxy in Docker with a config file, add a model, issue virtual keys with budgets, set fallbacks, wire health checks, and harden it for production.
- Intermediate
- About 2 hours to a working, budgeted gateway; a day to production-harden it
- 9 steps
Request a how-to
Tell us what you are trying to do and what you have already tried. We write the guides people ask for first, and we only publish commands we have checked against the official documentation.
Summaries and the research behind the guides
- Creating your own local model: the nine steps in brief
- Validating your AI in ten steps
- EU AI Act preparation and DPIA: the workflow in brief
- Securing and governing AI agents: injection, MCP, approvals
- How people and LLMs search for AI infrastructure answers
- How to write pages AI answer engines cite
- Question keywords in the AI governance market
- How-to guides vs docs vs blog
For coding agents and answer engines
The catalogue is available as JSON at /how-to/index.json, and each guide has a markdown copy at /how-to/<slug>.md. The same guides are listed in llms.txt.