This course equips programmers and developers with the skills to design, build, test, secure, and integrate Generative AI applications. It covers AI-assisted software development, large language model fundamentals, prompt engineering, API integration, embeddings, vector search, Retrieval-Augmented Generation (RAG), knowledge bases, AI agents, and workflow automation.
Participants learn to connect AI capabilities to existing applications and enterprise systems while addressing reliability, data access, security, performance, and operational costs. The course emphasizes engineering principles that apply across programming languages, model providers, and frameworks. A capstone project brings together the core components of an enterprise AI application.
Duration 10 Days – 70 hrs.
Objectives
- Use AI coding assistants to support development, documentation, refactoring, and code review while applying engineering judgment.
- Explain LLM concepts, including tokens, context windows, embeddings, model capabilities, and operational trade-offs.
- Design reusable prompts and validate structured model outputs.
- Integrate LLM APIs into applications with streaming, error handling, usage controls, and secure configuration.
- Build document ingestion pipelines and searchable knowledge bases using embeddings and vector search.
- Develop RAG applications that generate grounded responses with source attribution and permission-aware retrieval.
- Create tool-using AI agents with controlled execution, approval gates, and resource limits.
- Automate technical and business workflows through AI-enabled services.
- Test and debug prompts, retrieval pipelines, model responses, and agent behavior.
- Apply security controls to reduce prompt injection, sensitive-data exposure, unauthorized access, and tool misuse.
- Integrate AI services with databases, APIs, messaging systems, and enterprise applications.
- Monitor and manage application quality, reliability, latency, token usage, and cost.
Target Audience
- Software developers and programmers
- Backend and full-stack developers
- Application and solution architects
- DevOps and platform engineers
- QA automation and software test engineers
- Technical leads
- Integration developers
Prerequisites
- Programming experience in at least one language, such as Python, Java, C#, JavaScript, or TypeScript
- Familiarity with REST APIs and JSON
- Basic knowledge of Git and version control
- Basic database and SQL experience
- Familiarity with Docker and container concepts
- Basic understanding of authentication, authorization, and web application security
- Cloud computing and machine-learning knowledge is helpful but not required
Course Outline
Day 1 — AI-Assisted Software Development
Module 1: AI-Assisted Software Development
- AI coding assistants and development agents
- Inline completion and conversational coding
- Context windows and repository context
- Effective coding prompts and specification-driven development
- Project scaffolding and REST endpoint generation
- Code explanation and documentation
- Refactoring legacy code
- SQL and regular-expression generation
- AI-assisted unit-test generation and code review
- Hallucinated APIs, nonexistent packages, dependency risks, and licensing considerations
- Verification against official documentation and human review requirements
Hands-on activities
- Generate a small REST endpoint from a written specification.
- Ask AI to explain and document an unfamiliar codebase.
- Refactor tightly coupled code using dependency injection and repositories.
- Generate unit tests for existing business logic.
- Review deliberately flawed AI-generated code.
- Compare an AI-generated solution against the official library documentation.
Day 2 — LLM and Generative AI Fundamentals
Module 2: LLM and Generative AI Fundamentals
- Generative AI, foundation models, and practical transformer concepts
- Tokens, tokenization, and context windows
- System, developer, user, and tool messages
- Output variability, generation settings, and model-specific support
- Token limits and response truncation
- Embeddings and semantic similarity
- Model families, reasoning models, and general-purpose models
- Multimodal capabilities
- Hosted APIs and self-hosted models
- Selecting between prompting, RAG, and fine-tuning
- Latency, throughput, quality, and cost trade-offs
- Token usage and workflow cost estimation
Hands-on activities
- Inspect how different inputs are tokenized.
- Compare outputs using different temperature settings.
- Test the same task using multiple models.
- Compare keyword search with semantic search.
- Estimate the token usage and cost of a sample workflow.
- Identify which use cases require RAG, fine-tuning, or standard prompting.
Day 3 — Prompt Engineering for Developers
Module 3: Prompt Engineering and Structured Outputs
- Prompt structure and instruction hierarchy
- System prompts and application policies
- Zero-shot and few-shot prompting
- Concise reasoning summaries and limitations of model explanations
- Reusable prompt templates and variables
- Delimiters and handling untrusted input
- Structured JSON output, JSON Schema, and typed responses
- Function and tool-calling concepts
- Prompt versioning and configuration management
- Handling refusals, incomplete responses, and ambiguous requests
- Guardrails and response validation
- Information extraction and adversarial input handling
Hands-on activities
- Build a reusable prompt template.
- Convert free-form model output into structured JSON.
- Validate model output against a schema.
- Develop an information-extraction prompt.
- Test a prompt using normal, ambiguous, and adversarial inputs.
- Store and compare multiple prompt versions.
Day 4 — LLM API Integration
Module 4: Building Applications with LLM APIs
- REST API and SDK integration
- API keys, managed identities, and environment-based configuration
- Request and response structures
- Conversation history and state management
- Streaming responses
- Structured outputs and tool calling
- Timeouts, retries, exponential backoff, and rate limits
- Token budgets and cost controls
- Response caching and circuit breakers
- Logging and correlation IDs
- Provider abstraction and portability
- Building an AI-enabled backend endpoint
Hands-on activities
- Build a command-line LLM client.
- Create a REST API that accepts a request and returns an AI response.
- Add streaming to a frontend or API endpoint.
- Implement retry and timeout handling.
- Add token-usage and cost logging.
- Introduce a provider interface to reduce vendor lock-in.
Day 5 — Embeddings and Knowledge Bases
Module 5: Embeddings, Vector Search, and Knowledge Bases
- Embeddings, vector representations, and similarity metrics
- Vector databases and vector-capable relational databases
- Document loading, text extraction, and OCR considerations
- Chunking strategies, chunk size, and overlap
- Document metadata and access-control metadata
- Embedding generation and storage
- Indexing and re-indexing
- Semantic, keyword, and hybrid search
- Metadata filtering
- Document versioning and deletion
- Knowledge-base maintenance and freshness
Hands-on activities
- Extract text from sample documents.
- Divide documents using different chunking strategies.
- Generate and store embeddings.
- Implement semantic search.
- Add department, document-type, and date filters.
- Compare semantic, keyword, and hybrid search results.
Day 6 — Retrieval-Augmented Generation
Module 6: Building RAG Applications
- RAG architecture and use cases
- Document ingestion and retrieval pipelines
- Query processing and query rewriting
- Retrieval settings, top-k selection, filtering, and reranking
- Context construction and context-window management
- Grounded response generation and source attribution
- Handling insufficient evidence and unanswerable questions
- Conversation-aware retrieval
- Permission-aware document retrieval
- Distinguishing retrieval failures from generation failures
- RAG quality metrics and retrieval tuning
- Advanced and agentic RAG concepts
Hands-on activities
- Build a document-ingestion pipeline.
- Create a RAG-based question-answering API.
- Return source citations with every answer.
- Add an “insufficient evidence” response.
- Compare different chunk sizes and retrieval settings.
- Test the system using answerable and unanswerable questions.
- Add permission-aware document retrieval.
Day 7 — AI Agents and Automation
Module 7: Tool-Using AI Agents and Workflow Automation
- Workflow automation and agentic behavior
- Agent goals, state, memory, planning, and tools
- Tool descriptions and input schemas
- Database and external API tools
- Single-agent and multi-agent patterns
- Sequential and parallel workflows
- Planning and execution loops
- Approval gates and controlled autonomy
- Maximum steps, token budgets, and execution limits
- Idempotency and duplicate-action prevention
- Long-running jobs and background processing
- Agent observability, failure handling, and recovery
- Support-ticket triage and related automation use cases
Hands-on activities
- Create an agent with read-only tools.
- Add a database-search tool.
- Add an external API tool.
- Build a support-ticket triage workflow.
- Require approval before an agent performs a write operation.
- Add execution, cost, and time limits.
- Test tool failures, invalid parameters, and repeated actions.
Day 8 — Testing and Debugging AI Applications
Module 8: AI-Assisted Testing and Debugging
- AI-assisted unit, integration, and end-to-end testing
- Test-data generation, boundary cases, and negative tests
- Mocking LLM responses
- Deterministic and nondeterministic application behavior
- Golden datasets and prompt regression testing
- Semantic evaluation of model outputs
- Retrieval relevance, groundedness, and faithfulness
- Tool-selection accuracy and agent trajectory testing
- Load, latency, and cost testing
- Debugging model, retrieval, and orchestration failures
- Production feedback loops and continuous improvement
Hands-on activities
- Generate and review unit tests for an existing service.
- Mock LLM API calls during automated testing.
- Create a golden dataset of expected questions and answers.
- Build an automated prompt-evaluation test.
- Identify whether failures originate from retrieval or generation.
- Test an agent’s tool selection.
Day 9 — AI Application Security
Module 9: Securing Generative AI Applications
- AI application threat modeling
- Direct and indirect prompt injection
- Jailbreaking and system-prompt leakage
- Sensitive-data disclosure and insecure output handling
- Excessive agency and tool abuse
- Data poisoning and knowledge-base poisoning
- Embedding and retrieval risks
- Model denial of service and supply-chain risks
- Secrets management, authentication, and authorization
- Tenant and department isolation
- Input and output filtering
- Sandboxing, allowlisted tools, and parameter validation
- Approval controls for destructive or high-impact operations
- Audit logging, incident response, and OWASP guidance for LLM applications
Hands-on activities
- Threat-model a RAG and agent application.
- Test direct and indirect prompt-injection examples.
- Prevent unauthorized documents from entering retrieved context.
- Add role-based access control to the knowledge base.
- Validate generated commands and API parameters.
- Require approval for destructive or high-impact operations.
- Perform an AI application security review.
Day 10 — Enterprise Integration and Capstone
Module 10: Integration with Existing Systems and Production Operations
- AI service-layer architecture for existing and legacy applications
- REST, database, and event-driven integration
- Message queues, background workers, and asynchronous processing
- Integration with CRM, ERP, help desk, and document systems
- Identity integration and human approval workflows
- Transaction boundaries, idempotency, and duplicate prevention
- API gateways and fallback behavior
- Containerization and CI/CD
- Feature flags, staged rollout, migration, and rollback
- Model and prompt versioning
- Health checks, structured logging, and observability
- Monitoring quality, latency, reliability, and cost
Hands-on activities
- Integrate an AI service with an existing REST application.
- Read approved knowledge from a database or document repository.
- Process long-running requests through a background worker.
- Add authentication and role-based authorization.
- Containerize the application.
- Add health checks and structured logging.
- Implement a fallback when the model service is unavailable.
- Deploy a new prompt using feature flags.
Capstone Project: Enterprise AI Knowledge Assistant
The capstone combines components developed throughout the course into an integrated application.
- Connect an AI-enabled backend service to an approved document collection or knowledge repository.
- Implement document ingestion, embeddings, and permission-aware retrieval.
- Generate grounded answers with source citations and insufficient-evidence handling.
- Add a controlled tool for database lookup or external API access.
- Apply authentication, authorization, input validation, and approval controls where needed.
- Incorporate application tests, error handling, and fallback behavior.
- Add logging and token-usage, latency, and cost monitoring.
- Package the application for deployment and document its architecture and operational requirements.

