An AI-first CMS: AI operates, people govern

Every content management system (CMS) I know was designed for a person. A writer opens a form, fills in a title and a body, and clicks publish. AI arrived later, as a button inside that form. I keep wondering what we’d build if we started the other way round: a CMS designed for an AI agent to operate, with people in charge of what it may do.
What’s out there today
I went looking for a CMS that already works this way. As of October 2026, here’s what exists, in three layers:
| Layer | What the AI does | Who has the last word | Examples |
|---|---|---|---|
| AI in the editor | Drafts, rewrites, translates and writes alt text when a person asks | The person in the editor | WordPress 7.0 with its AI plugin, Drupal CMS 2.0, Sanity’s Content Agent |
| Outside agents | An outside agent creates and edits content through a Model Context Protocol (MCP) server | A person’s approval, or the permissions a person gave the agent | WordPress.com, Strapi, Prismic |
| Agents on triggers and schedules | Agents start work on their own: audits, translations, checks | A person’s approval, or the permissions a person gave the agent | Kontent.ai, Optimizely Opal, Storyblok |
The words “AI-first” and “agentic” are already in use. Sitecore relaunched its platform in November 2025 under a headline about the “AI-first era”. Kontent.ai calls itself the world’s first agentic CMS, and its product page is clear that its AI doesn’t publish on its own. In every established product I checked, what sits underneath is still an editor built for people, with agents working through people’s permissions and approvals.
Two projects I found were designed around the agent from the start, LightCMS and AICMS. Both are small and months old, and both keep an admin panel for people beside the agent.
The closest thing isn’t a CMS
StackOne replaced Webflow in early 2026 with an Astro site kept as files in a repository. People describe a change in plain words, Claude Code makes it on a branch under a CLAUDE.md file of rules, and four AI reviewers check each pull request (a proposed change waiting for review). In May 2026, Sentry described dropping its headless CMS for the same kind of setup: people who don’t write code change the site’s Markdown files through Claude Code skills (saved instructions for a task) that open a pull request for review. For documentation sites, Mintlify’s agent goes a step further: it runs when code changes or on a schedule, and opens the pull request itself.
This setup works, but it’s assembled from developer tools. The review desk is GitHub, and the rule book is a text file that Claude Code’s documentation describes as context for the agent, not configuration it enforces. So the agent can drift from those rules, unless someone also writes a check that blocks any change that breaks them.
What it could look like
Picture that loop (rules, an agent, review, publish) as one product, built for the agent to operate and for people to govern. Drupal’s founder put the split at about 80% of the work for the AI and 20% for people: direction, approval and responsibility. These are the four pieces I’d want:
- Tools, not forms. The agent is the main user, so the first interface is a set of tools it can call over MCP, and forms become the fallback. Most of the big CMSs already speak MCP; the difference is that here the tools come first.
- The rule book is content. It lives in the CMS and is edited like any page: voice, words to avoid, facts that must stay true, who approves what. People write the rules in plain language, and the CMS turns every rule it can into a check that stops a change that breaks it.
- Facts with sources, pages as output. As a CMSWire piece puts it, agents multiply whatever mess a repository already holds. So the agent shouldn’t copy a price or a date into every page that mentions it: each fact lives once, with its source and its owner, and pages are built from it.
- The review desk is the home screen. Each change arrives as a diff (what changed, side by side) with the agent’s reasons and sources. Routine changes pass on the checks alone; anything risky waits for a person, the way Smartling says it already runs translation: AI first, and a human linguist only when a job needs one. Big batches are reviewed by sampling. Every change is logged with the agent, model and prompt that made it, as Drupal’s founder sketched in 2025. And what people correct at the desk goes back into the rule book.

One smaller piece: an AI-first CMS would also publish for agents, with a plain Markdown copy beside every page. I’d keep that part modest for now, because there’s little sign yet that agents ask for such files. In Ahrefs’ logs, 97% of llms.txt files (a Markdown map of a site for language models) got no requests in May 2026, and Google says that appearing in its AI features needs no special file at all.
Why people stay in charge
It’s tempting to see the human gate as a compromise. I think it’s the feature.
- The law. Since 2 August 2026, the European Union’s AI Act has required AI-generated text to be disclosed as such when it’s published to inform the public on matters of public interest. The exception is text a person has reviewed, with someone holding editorial responsibility for it. That exception is the human gate.
- Search. On 1 October 2026, Google’s guidance began asking publishers to fact-check all AI output by hand before publishing it, including titles, meta descriptions and alt text.
- Accuracy. Even when a model only summarizes a document it was given, one public leaderboard measures hallucination rates from under 2% to around 24%, depending on the model.
- Trust. In a Reuters Institute survey across six countries, 12% of people were comfortable with news made entirely by AI, and 43% with news a person leads and AI helps with.
What I’m unsure about
- Review fatigue. If an agent proposes changes faster than anyone can read them, people start saying yes without reading, what the AI Act calls automation bias. Sampling and routing by risk should help, but they sit uneasily with Google’s ask to check all AI output by hand, and with the AI Act’s exception for text a person has reviewed. I don’t know yet where the line between routine and risky belongs.
- Originality. AI helps with summarizing, translating and tidying, as long as someone checks it. I’m less sure where something genuinely new comes from when the agent writes first.
- Security. An agent that can publish is a target. Rules files can carry hidden instructions. In 2025, the MCP endpoint of a WordPress AI plugin had a flaw rated 9.8 out of 10. And the Open Worldwide Application Security Project (OWASP) now lists the top risks for agents, from goal hijacking to tool misuse.
- The label. I’m using “AI-first” myself, and if it ends up on every product page, it could stop meaning anything. Gartner already warns about agent washing, relabelling assistants as agents. It also expects more than 40% of agentic AI projects to be cancelled by the end of 2027.
- The flood. Graphite estimates that AI already writes about as many online articles as people do. Google’s spam policy calls it scaled content abuse when AI is used to generate many pages that add no value. The gate is there so an AI-first CMS doesn’t just make those pages faster; I’m not sure it’s enough on its own.
Where to start
I wouldn’t start this with an editor. I’d start from what already works (files in a repository, a coding agent and pull requests) and build the pieces it’s missing:
- An MCP server from day one, so any agent can be the operator.
- A rule book someone who doesn’t write code can edit, with every rule that can be tested enforced before a change goes live.
- Facts stored once, each with its source and its owner.
- A review desk that isn’t GitHub: the change, its reasons, its sources, and one button.
- Routing by risk, so people review what matters and the checks handle the rest.
The CMS was built for the writer. The next one could be built for the agent to operate, and for the people who govern what it may say.
If you’d like to build this, with me or without me, or to help fund it, I’d love to hear from you.