Choose a useful first project

Learn AI, then build something you can explain.

Four practical routes through the free library, with honest starting points, things to make and limits on what each route covers.

By Mickarle Wagstaff-Irons - Micky Irons

Prepared with AI assistance. Published by Mickai LTD. Course and reference check: 28 September 2026.

Choose a route, not a pile of tabs

The current library has 57 published free courses with PDF workbooks. You can read the lessons without an account. These paths organise existing courses; they do not create new qualifications or require you to finish the whole library.

The placement quiz can suggest a level. You can also choose directly. Skip material you can already demonstrate, return when a prerequisite is unfamiliar, and keep the output from each exercise. Free study does not make external tools, hosting or paid model usage free.

1. AI in plain English

Start here: no coding or technical background. Paper is enough for many early exercises. If you use a chatbot, use invented examples and check the provider's current account, age and data rules first.

  1. What is AI? A plain-English starter (Level 1, about 75 minutes). Explain a model, a prompt and a plausible mistake in your own words. Keep one example of an answer that needs checking.

  2. Your first prompts: how to ask AI for what you actually want (Level 1, about 120 minutes). Turn a vague request into a task with context, constraints and a useful output format. Compare the result with the original request.

  3. The free AI toolkit: how to choose tools and stay safe (Level 1, about 120 minutes). Choose a small tool set for one purpose. Record what each tool may cost and which information you will keep out of it.

  4. Stay safe with AI: scams, fake media and your privacy (Level 1, about 100 minutes). Practise checking a suspicious message or image through an independent channel, without sending private information to an assistant.

Make this: a one-page task card with your goal, invented input, prompt, result, two checks and one reason to stop. A useful answer is one you can substantiate, not simply one that sounds confident.

Ready to move on when: you can explain what the tool did, identify an unsupported claim and improve the task without copying private material into it. If you already enter formulas and fill them down, Automate a spreadsheet workflow with AI, checks and an audit trail (Level 2, about 120 minutes) is a practical next project. It assumes that spreadsheet skill; it is not a first lesson in using a computer.

2. Build a website or a small app

Start here: you can manage a folder and use a text editor. A simple information page can be built with free local tools. Optional publishing depends on the host's current limits and permitted use; a custom domain or model API can add costs.

  1. Build and launch a website with AI (Level 2, about 120 minutes). After the prompts course, plan one page for one audience. Draft the content, inspect the HTML and CSS, and use the launch checklist.

  2. HTML: build a meaningful, accessible page (Level 2, about 130 minutes). Build the structure yourself: meaningful headings, links, labels and alternative text. This has no earlier coding prerequisite.

  3. CSS: responsive layouts, grids and typography (Level 2, about 140 minutes). Continue from the HTML workbook or its finished event page. Check a narrow viewport, longer text and readable typography before adding effects.

  4. Git for AI builders: commits, branches and pull requests (Level 2, about 125 minutes). Learn commits, branches and reviewable changes. First practise opening a terminal and changing folders. Local Git is useful before you create a remote repository.

Make this: an information page with a clear heading, useful navigation and a keyboard-operable contact link, plus a change log and a known-good version you can restore. Do not put passwords, private customer information or API keys in its files or Git history. A public repository is public publishing.

GitHub is one possible remote hosting and collaboration service. The Git workbook teaches the workflow; it is not a promise that every account screen or hosting plan stays unchanged. Review the current service terms before publishing a business site.

When you need interaction or an assistant

JavaScript: the browser, events and application state (Level 3, about 140 minutes) follows the HTML and CSS event-page project. Start with a button and visible state before adding forms that collect data. Build your first app with an AI coding assistant (Level 2, about 120 minutes) uses supplied example code, so an assistant account is helpful rather than required.

Code for as little as possible: VS Code, OpenCode and app builders (Level 2, about 125 minutes) belongs after the first-app work. It compares editor, model and app-builder costs. Its offline calculator requires Python 3; use Python: from first script to a useful automation (Level 2, about 140 minutes) first if that is new. The course does not make a paid backend free or guarantee identical agent features in every editor.

For a later Hugging Face model-card and licence exercise, Open model licences, datasets and deployment obligations (Level 3, about 110 minutes) assumes open-weight model vocabulary and enough Python to run a script. It is not a beginner Hub or Spaces deployment course. Use Which AI model should I use? Picking the right AI for the job (Level 2, about 120 minutes) for the model-choice vocabulary first.

Ready to move on when: you can explain your files, test the page with a keyboard and at a narrow width, identify a changed line, and restore the previous version. An AI-generated page is still yours to review.

3. Governance and AI cybersecurity

Start here: understand basic AI limitations. The reading route and the coding route have different prerequisites. Do not put a real system under test merely because you completed a workbook.

AI governance: risk registers, evidence and human accountability (Level 3, about 115 minutes) introduces hazards, owners and evidence. Start with chapters 1 and 2. Its numerical scoring and oversight worked examples are under review; do not treat them as validated residual-risk estimates or a release decision. The coding chapter requires Python. The page below provides a useful decision record without relying on those numerical examples.

Privacy and data minimisation in AI applications (Level 3, about 100 minutes) approaches data from an organisation's perspective and requires enough Python for its script. Its legal examples are limited in jurisdiction. A statement about one country is not a conclusion about every place where your users, staff or suppliers are located.

  1. The loop harness: how AI agents actually run (Level 3, about 90 minutes). Read how an agent chooses a tool, receives results and reaches a stop. Draw who is allowed to perform each action.

  2. Prompt injection: threat analysis and defensive testing (Level 3, about 135 minutes). After the loop material and Python preparation, examine the offline stand-in assistant. Distinguish an untrusted document from an instruction with authority.

  3. RAG and knowledge bases, step by step (Level 3, about 100 minutes). Understand chunks, retrieval, citations and evaluation before building a private knowledge-base exercise.

  4. Permission-aware retrieval and private knowledge bases (Level 4, about 180 minutes). For readers comfortable with Python functions, sets, classes and tests: practise permission filtering with fictional data.

  5. Threat-model an agent and its tool boundary (Level 4, about 180 minutes). After the loop and injection courses, practise bounded tool authority and tests in a local Python 3.12 exercise folder.

Make this: a boundary record naming the user, data source, allowed action, owner, proposed control, test input, expected denial and observed result. Mark unrun tests NOT RUN. Include an unauthorised user, a revoked permission and an attempted action outside the task.

Ready to move on when: you can explain both an allowed path and a denied path, preserve the evidence and say who can stop the work. A passed synthetic exercise is not a penetration test, production security assurance or proof of compliance. On-premises hosting still needs access control, updates, recovery and accountable operation.

4. Leadership, ISMS and AI readiness

Start here: a business problem you can describe without naming a tool. Leaders can begin with the plain-English route and Which AI model should I use? Picking the right AI for the job (Level 2, about 120 minutes). You do not need to operate a model to ask who benefits, what might fail and which evidence would change a decision.

This is a preparation roadmap, not an available full CEO or ISMS course. Work through a fictional or sanitised example and write four short records:

  1. Purpose and alternatives: name the affected people, current process and desired outcome. Compare AI with a process improvement or a simpler non-AI tool. Separate a hypothesis from an observed benefit.
  2. Data readiness: list each source, owner, sensitivity, access rights, quality concerns, provenance, retention and permitted use. Unknown permission is a question to resolve, not consent.
  3. Decision rights and resources: name one accountable decision owner, the review roles, cash and staff-time limits, stop conditions and next review date. A discovery budget does not authorise production use.
  4. Evidence and recovery: define the cases you will check, including harmful failures. Record what has actually been tested, who may approve a bounded next step, and how work is paused or reversed.

Make this: a one-page discovery brief plus the source inventory. Use a decision of proceed with bounded discovery, hold for evidence, or stop. A well-supported hold is a useful outcome. Do not translate saved minutes directly into cash savings without explaining whether paid capacity or spending would actually change.

Dedicated AI readiness, founder, CEO, governance, ISMS and AI management-system courses are part of the planned premium programme. They are not currently open for enrolment. Mickai's AI readiness page describes the related company programme. Trust Agent is published by the same company; this is a relevant service link, not an independent endorsement or a guarantee of results.

What the compliance material covers today

Record your organisation's entity, operating markets, affected people, sector, data locations and role in the AI supply chain. Choose the jurisdiction or jurisdictions that matter to your case. If applicability is unresolved, name a review owner and leave the conclusion open. There is no worldwide compliance selector or comprehensive country-by-country course on this site today.

Current coverage and its limits, checked 28 September 2026
TopicUseful material nowStill needed
ISO/IEC 27001 and ISMSGeneral risk, ownership and data exercises. ISO's public overview describes an information security management system.A complete ISMS implementation course, organisation-specific scope and reviewed evidence. A workbook is not organisational certification.
ISO/IEC 42001 and AI management systemsIntroductory governance vocabulary. ISO identifies a management-system standard for AI, with a different scope from an ISMS.The dedicated practical programme is planned. We do not reproduce paid standard clauses or claim an accredited qualification.
EU AI ActLimited references in governance and data courses; official entry points below.A complete applied course and case-specific analysis of actor, use, risk category, jurisdiction and applicable dates. Do not infer applicability from a course score.
AI risk governanceHazard and accountability reading, plus the discovery and decision records on this page.Review of the numerical governance examples and evidence from your actual context. NIST's AI RMF is voluntary guidance, not legal approval.
AI cybersecurityOffline injection, retrieval-permission and tool-boundary exercises for readers with the stated technical skills.A beginner-to-practitioner bridge and real-system evaluation of deployment, suppliers, operations and recovery. Exercise results do not certify a system.

Official starting points

These are selected primary references, checked on 28 September 2026. They are not a legal opinion, a complete standards mapping or evidence that your organisation meets a requirement. Keep the edition, source date and unresolved questions in your own record.

Free library, planned premium programme

Available now: the published foundation library and its free PDF workbooks. It includes both beginner and advanced technical topics. Read the library and each course's prerequisites to choose. The free-library target is 75 courses; a target is not the current count.

Planned, not open for purchase: twenty premium courses covering business leadership, AI readiness, governance, ISMS, data engineering, cybersecurity, evaluation, agents and deployment. The proposed price is GBP 100 per course, subject to final terms. Content, workload review, final learning assets and the payment service are still being prepared. There is no working premium checkout or enrolment to use here.

Referral credit is proposed, not usable: the design is a 10% referral credit with six-month validity. Final eligibility, calculation, availability, expiry, refund and redemption terms are not released. No credit can currently be earned or spent through this site. Do not make a purchase or referral on the assumption that this proposal is an active offer.

Certificates: the current device-generated completion certificate is self-declared and not accredited. The planned assessed flow requires a score strictly above 80%, so exactly 80% fails, together with meaningful course-specific evidence, timed assessment and appropriate accommodations. That verified assessment and issuance service is not live for the free library or the premium programme. Reading this path does not award a qualification.

Give the next session one clear finish

Choose one linked course and a short session that fits your circumstances. Write what you intend to make, what you already know and what you will check. Keep the before-and-after files or notes. If a tool is unaffordable, an account is unavailable or a prerequisite is missing, use the supplied paper or local example where available, or pause and do the preparation first.

At the end, record: what I made; what I checked; what failed; what remains unknown; my next safe step. Those five lines make the learning useful to a future collaborator. They also make an honest stopping point when the next step is not yet justified.

Choose a free course or find your starting level.