C&EO Creative
Covering the business of web design
Tuesday · Sep 1 2026
Subscribe →
Platforms

Agentic AI Enters the CMS: What "AI Taking Direct Action" Means for Agency Workflows

Core WordPress, Drupal, and the Salesforce-Contentful deal all point the same way: the CMS is becoming something an agent can operate. The agency question is who approves.

The distinction that matters in the phrase “agentic CMS” is narrow and easy to miss. A model that drafts a blog post you paste into the editor is not agentic. An agent that reads a trigger, decides an action, changes a published page, and moves on without anyone prompting it — that is a different category, and it is the one the major platforms shipped infrastructure for over the past year.

The shift is not vendor marketing this time. It is in core.

What actually shipped

WordPress. The Abilities API arrived in WordPress 6.9 as a common interface that AI agents, workflow automation tools, and plugins can use to interact with WordPress. WordPress 7.0 “Armstrong,” released in May, added a client-side counterpart for abilities like navigating the admin or inserting blocks, plus a Connectors API for registering connections to external services — API key management, provider discovery, and a Settings → Connectors screen — and an AI Client in core that lets WordPress talk to generative models directly.

Read that as a stack rather than a feature list. Core now has a way to describe what WordPress can do in machine-readable terms, a way to hold credentials for a model provider, and a client to call one. The pieces required for something external to operate a WordPress site are in core, not in a plugin.

Drupal. The Drupal CMS 2026 strategy is blunter than most vendor roadmaps: “AI is not a feature in Drupal CMS. It is the lens through which every part of the product is evaluated.” The stated targets include site installation and setup achievable via a single prompt, AI-assisted content-type creation and view configuration, and AI-augmented editorial review, with the overall program aimed at June 2028.

Drupal’s AI Agents framework already supports text-to-action agents that manipulate configuration or content from instructions. Maturity is uneven and the project says so — the foundation and editorial modules are production-ready, multi-step automators and the context control center are pilot-ready, and fully autonomous agents such as the Views agent remain experimental.

Contentful. On June 1, Salesforce signed a definitive agreement to acquire Contentful, a composable content platform used by more than 4,800 brands, positioning it as a content layer for Customer 360, Headless 360, and Agentforce. The transaction is expected to close in Q3 of Salesforce’s fiscal 2027 subject to regulatory approval; Salesforce says Contentful will continue with the same platform, APIs, and support model. Terms were not disclosed in the announcement, and press estimates have varied.

The principle everyone is converging on

Drupal states it as a design rule: “AI assists and suggests; humans retain final authority over structural and editorial decisions.”

That is the whole ballgame for agencies, and it is worth noticing that the platform with the most explicit agentic ambition is also the one writing the human-authority principle into its strategy document. The strongest agent workflows in practice are not fully autonomous — an agent prepares a change and an editor reviews it. Everything downstream of that principle is an approval-design problem, which is a thing agencies already know how to do.

Where this actually bites on client work

Credentials now live in the CMS. The Connectors screen means a WordPress site can hold a model provider’s API key. That key bills someone, and if the agency put it there, it may be billing the agency. Decide whose account, whose spend cap, and whose rotation schedule before a single site gets one — and treat a model key with the same care as a payment gateway credential, because it has a meter attached.

“It can” is not “it should.” An agent that can edit published content will, at some point, edit published content wrongly. The mitigation is not to distrust the agent; it is to make sure agent-originated changes land in a reviewable state. Draft or pending, never direct-to-published, on any client site where a bad page has commercial consequence.

Attribution in the audit trail. When a change is made by an agent acting on a trigger, the revision history should say so. This is mundane and it is the first thing a client will ask about the first time something is wrong.

Scope language. Retainers written before this year generally do not say whether autonomous content changes are in or out of scope, who is accountable for an agent’s output, or what happens when a model provider changes pricing mid-term. Those are contract questions, not technical ones, and they will get answered either deliberately now or awkwardly later.

The honest read on maturity

Drupal’s own maturity tiers — production-ready foundations, pilot-ready automators, experimental autonomous agents — are a fair description of the whole category, not just Drupal’s part of it. The plumbing is real and shipped. The autonomy on top of it is early.

That combination argues for a specific posture. Build on the infrastructure now, because it is in core and it is stable. Pilot agent-initiated actions on internal properties and low-stakes client surfaces. Keep a human on the approval step for anything a client’s revenue touches, and do not sell the autonomy as a capability until you have watched it be wrong a few times and seen what the failure looks like.

The agencies that get value from this in the next year will be the ones treating the agent as a very fast junior who does not get commit access.

The Brief

The web-design industry, in one email.