CMSAI agentsOpen source

An AI-first CMS: AI operates, people govern

Every content management system was designed for a person at a form, with AI added later as a button. What would we build if we started the other way round: a CMS for an agent to operate, with people in charge of what it may do? Our founder's design, and why we prototype it in FluentCMS.

Amir Pournasserian · October 8, 2026 · 4 min read

Based on published research

This note summarises research our founder published in full, with the comparison tables and method, at An AI-first CMS: AI operates, people govern.

Every content management system we know was designed for a person. A writer opens a form, fills in a title and a body, and clicks publish. AI arrived later, as a button inside that form. Our founder’s October 2026 note asks what we would build if we started the other way round: a CMS designed for an AI agent to operate, with people in charge of what it may do. This is the idea in short, and why it matters to us: FluentCMS, our open-source CMS for .NET, is where we try it.

What exists today

As of October 2026 the market has three layers, and in all of them a person-first editor sits underneath:

LayerWhat the AI doesWho has the last wordExamples
AI in the editorDrafts, rewrites, translates, writes alt text when askedThe person in the editorWordPress 7.0 with its AI plugin, Drupal CMS 2.0, Sanity’s Content Agent
Outside agentsAn agent creates and edits content through an MCP serverA person’s approval, or the permissions given to the agentWordPress.com, Strapi, Prismic
Agents on triggers and schedulesAgents start audits, translations and checks on their ownA person’s approval, or the permissions given to the agentKontent.ai, Optimizely Opal, Storyblok

The words “AI-first” and “agentic” are already in use on product pages. In every established product checked, what sits underneath is still an editor built for people, with agents working through people’s permissions.

The closest thing is not a CMS at all. Several companies have replaced their website CMS with a repository of files, where a person describes a change in plain words, a coding agent makes it on a branch under a file of rules, and reviewers, human and AI, check the pull request before it goes live. It works, and it is assembled from developer tools: the review desk is GitHub and the rule book is a text file the agent may drift from unless someone writes a check that enforces it.

Four pieces of an AI-first CMS

Tools, not forms. The agent is the main user, so the first interface is a set of tools it can call over the Model Context Protocol. Forms become the fallback.

The rule book is content. Voice, words to avoid, facts that must stay true, who approves what. People write the rules in plain language, in the CMS, and the CMS turns every rule it can into a check that stops a change that breaks it. The rule stops being advice to the agent and becomes a constraint on it.

Facts with sources, pages as output. Agents multiply whatever mess a repository already holds. So the agent should not copy a price or a date into every page that mentions it. Each fact lives once, with its source and its owner, and pages are built from it.

The review desk is the home screen. Each change arrives as a diff with the agent’s reasons and sources. Routine changes pass on the checks alone; anything risky waits for a person. Big batches are reviewed by sampling. Every change is logged with the agent, the model and the prompt that made it, and what people correct at the desk goes back into the rule book.

Why people stay in charge

It is tempting to see the human gate as a compromise. The note argues it is the feature, and the reasons are external. Since 2 August 2026 the European Union’s AI Act has required AI-generated text published to inform the public on matters of public interest to be disclosed as such, with an exception for text a person has reviewed under editorial responsibility. On 1 October 2026 Google’s guidance began asking publishers to fact-check all AI output by hand before publishing it. Measured hallucination rates for summarising a document a model was given range from under 2% to around 24% depending on the model. And in a Reuters Institute survey across six countries, 12% of people were comfortable with news made entirely by AI, against 43% for news a person leads and AI helps with.

What is still unresolved

The note is honest about what it does not know. Review fatigue: if an agent proposes changes faster than anyone can read them, people start approving without reading. Originality: AI summarises, translates and tidies well; where something genuinely new comes from when the agent writes first is less clear. Security: an agent that can publish is a target, rule files can carry hidden instructions, and in 2025 the MCP endpoint of a WordPress AI plugin had a flaw rated 9.8 out of 10. And the flood: AI already writes about as many online articles as people do, and a gate that makes bad pages slower to publish may not be enough on its own.

Why we care

We maintain FluentCMS, an open-source CMS on ASP.NET Core and Blazor that already ships an AI writing assistant, which is the first of the three layers above. The design in this note is the direction we are prototyping in it: tools over MCP first, rules that become checks, facts stored once, and a review desk at the centre. It is also the shape of the content systems we build for clients, where the question is never whether AI will write, but what it may publish and who answers for it.

The full note, with sources for every claim, is at the link above. The open-source project is at our open source page.

Working on this?

These are the patterns we use on client work. Tell us what you are building and we will say how they apply.

Book an AI consultation