Applied & Agentic Systems

How prompting, RAG, and agents combine to turn a single trained LLM into a real, capable application

Every previous lesson built toward one artifact: a trained, servable LLM that can take text in and produce text out. This final part of the course covers how real applications turn that single capability into systems that can answer questions about private data, take actions in the world, and complete multi-step tasks.

The core limitation: a frozen, closed-book model

A deployed LLM has two structural limits worth naming explicitly:

  • Its knowledge is frozen at training time. It knows nothing about events after its training data was collected, and nothing at all about private data it was never trained on (your company's internal docs, a user's account details).
  • It can only produce text. On its own, it cannot look anything up, run code, query a database, or send an email — whatever "actions" it appears to take in an application are actually the application acting on the model's text output, not the model doing anything itself.

Every pattern in this part of the course is a way of working around one or both of these limits. The most general of those patterns — an LLM run in a loop, with the application executing tools on its behalf and feeding results back in — looks like this:

At every step the model either answers directly or asks the application to run a tool and hand the result back into its context — and it keeps looping until it has enough to answer. Three lessons build up to that loop one piece at a time:

Read them in that order — each is a heavier lever than the last, and agents commonly use retrieval as just one of their available tools, so the agent lesson assumes you've seen the RAG one. Every one of those levers is also a new attack surface, covered separately in AI Security once you've seen what there is to attack.

Course recap

Across these seventeen lessons: probability and MLE as the reason loss functions look the way they do, learning as loss minimization via gradient descent, backpropagation as the mechanism that makes that tractable at scale, the practitioner tooling (PyTorch, Hugging Face, and friends) that turns that math into runnable code, CNNs and transformers as two different architectural answers to "what structural assumptions should the network encode," diffusion models and GANs as a different problem entirely (generation, not prediction), the multi-stage recipe (pretrain → fine-tune → RLHF) that turns a transformer into an LLM, reinforcement learning as the actual algorithm family behind that last step, the engineering (KV caching, batching, quantization) that makes serving one practical, benchmarks and evaluation as the (imperfect) way to know if any of it worked, prompting, retrieval, and agentic tool use as the patterns that turn a single trained model into real, capable applications, and finally AI security as the reminder that a capable, tool-using system is also a bigger attack surface. Each layer builds directly on the one before it — which is exactly why this course was ordered the way it was.

On this page