03 Aug 2026
Drupal.org aggregator
The Drop Times: Public Code Must Survive the Contract
Public software is easiest to celebrate at launch, when a service is delivered, a repository is published, and an institution can point to visible progress. Its harder test begins after the original contract ends. Security response, documentation, upgrades, knowledge transfer and operational ownership must continue even when the delivery team or supplier changes. The EU Open Source Strategy, published by the European Commission on 3 June 2026, treats procurement, deployment, maintenance and governance as parts of the same software lifecycle.
Public procurement should therefore test continuity rather than initial delivery alone. Buyers need to know whether data, configuration and documentation can be transferred; whether another supplier can operate the service; whether publicly funded improvements can be reused; who will handle vulnerabilities and dependency updates; and how long transition support will remain available. An open licence can widen the range of possible suppliers, but that choice remains theoretical when system knowledge, access procedures or maintenance budgets stay with the incumbent. Avoiding lock-in requires both legal permission and the practical capacity to act on it.
The strategy proposes an Open Source Maintenance Instrument, dependency analysis, stewardship support and common security baselines for public repositories. These measures recognise that testing, release management, vulnerability response and documentation are infrastructure work rather than incidental volunteer activity. Drupal 7 reached end of life on 5 January 2025, but its source code remained available after community releases, fixes and security advisories ended. LocalGov Drupal offers a concrete model of organised stewardship by bringing councils and suppliers into shared product governance, technical maintenance and a cooperative structure intended to support financial sustainability.
Public money should produce more than software that can still be downloaded after the original team leaves. Contracts should fund security work, upgrades, current documentation, supplier handover, upstream contribution and governance across changes in vendors and budget cycles. Europe's open-source ambitions will achieve little if institutions publish more code without retaining the capacity to operate, improve and transfer it. Public code becomes infrastructure only when responsibility survives delivery.
Follow The DropTimes on LinkedIn, X, Bluesky, and Facebook, or join #thedroptimes on Drupal Slack.
This issue of Editor's Pick was written and curated by Kazima Abbas.
03 Aug 2026 1:52pm GMT
Drupal AI Initiative: Move Fast, Stay On-Brand: How Drupal AI Delivers Both
Author: Will Huggins
In our previous blog posts, we've talked about how our growing ecosystem - now backed by 32 global partner organisations and a dedicated delivery team - is structured to build a secure, stable, and highly integrable AI-native digital experience platform.
So what does this mean for your day-to-day digital communications and marketing operations? How do you translate this into improved experiences for your audience, higher conversion rates, and reduced cost?
To win in the age of AI, digital leaders don't just need faster ways to generate content or build great digital experiences. They need a platform that helps them move at maximum speed, while still maintaining the highest quality and content standards.
Here is an inside look at the key features on the Drupal AI 2026 roadmap, focused on the outcomes that matter most to digital communications and marketing teams: speed, brand safety, and measurable ROI.
"Prompt-to-Published" Page Building (Using Your Real Design System)
Many AI-powered page builders on the market suffer from what digital leaders call "AI Slop": random, messy, raw HTML blocks based on generic AI models. These pages can break your site's layout, look wildly off-brand, fail accessibility standards, and create the dreaded 'technical debt' for your developers to clean up.
Drupal AI's upcoming Canvas AI Page Builder operates under a completely different paradigm. It is natively component-aware.
- You can feed Canvas AI a marketing brief, a PDF, or even a screenshot. Instead of writing custom code, the AI inspects your design system, selects the most relevant, pre-approved, accessible brand components, places them in a logical conversion layout, and drafts campaign-specific copy directly within them. Your marketing team can go from a brief to a beautifully structured, accessible landing page in minutes. You get complete visual design freedom without ever breaking brand guidelines or waiting in a developer's queue.
The Brand Guardrail: Localised Nuance & Centralised Brand Voice
A major anxiety for marketing teams is brand dilution. If your team is using disconnected AI tools, your brand voice can quickly fragment, sounding professional on one page and generic on another.
Drupal AI solves this by embedding a centralised Context Control Centre directly into the CMS. This serves as the single source of truth for your brand's identity and governance rules.
- Authored Context: You define your style guides, brand vocabulary, audience personas, and strict regulatory boundaries (such as HIPAA, GDPR, or accessibility standards) once. Every AI-assisted content generation task automatically adheres to these guardrails.
- Hyper-Local Translation: For global marketing departments, translation is rarely word-for-word. Under the 2026 roadmap, Drupal AI's translation workflows don't just translate text; they analyse local nuance and adapt your localised content to fit regional cultural contexts while strictly preserving your core brand voice.
You can scale your global content footprint across multiple regions and channels, confident that every single piece of copy, everywhere, sounds exactly like you.
Closed-Loop Performance: Self-Optimizing Digital Experiences
Today, your content lives in the CMS, but your performance data is trapped inside a web analytics dashboard (like Google Analytics or Matomo), and the two systems rarely talk to each other. As a result, marketing teams often miss trends, fail to optimise low-performing pages, and struggle to scale what actually works.
Drupal AI is built to close this loop by bringing performance intelligence directly into the content creation interface.
- Intelligent Website Improvements: Drupal AI integrates directly with your analytics platform. Instead of merely showing you a static traffic report, background AI agents analyse user journeys and conversion drops.
- Actionable Optimisations: If a high-value landing page is underperforming, the AI agent automatically flags it and proposes concrete layout or copy optimisations - such as a more compelling call-to-action or a tighter, clearer headline - based on what is historically proven to convert.
No more digging through dashboards to find what's not working. Your website becomes a living, self-optimising engine, learning what works best for your audience and handing ready-to-publish optimisations directly to your content editors, bridging the gap between data and action.
Built-In Governance: Keeping Humans (and IT) Firmly in the Loop
Speed is meaningless if your IT department or compliance team vetoes your tools due to security risks. To build an AI platform organisations can trust, Drupal AI treats security and governance as structural priorities, not afterthought add-ons.
Unlike lightweight SaaS tools that operate outside of your corporate governance, Drupal AI operates entirely within your existing approval workflows and editorial permissions.
- Human-in-the-Loop Safeguards: AI agents can propose layouts, drafts, and SEO metadata, but they cannot publish them autonomously. Every change is staged in a revision branch, allowing your marketing managers to review, edit, or reject changes before they ever go live.
- Data Sovereignty and Security: Advanced security filters automatically sanitise and strip sensitive customer or corporate data before it is ever sent to an external Large Language Model (LLM). This shields your organisation from data leaks and compliance breaches.
This means you get the agility of generative AI backed by enterprise-grade, auditable, secure workflows: the kind of governance IT teams look for.
Own Your Digital Destination
The future of digital experience is being built on open-source, model-agnostic foundations. By giving your marketing team visual page building, centralised brand context, and performance-driven optimisation within an enterprise-grade secure environment, Drupal AI is paving the way for digital teams to operate at maximum velocity with zero brand risk.
The future of open-source digital experience is being built right now. If your digital product or content marketing teams are ready to experience what is possible today, explore our progress and try the live demo.
03 Aug 2026 7:46am GMT
Talking Drupal: TD Cafe #020 - AI & Development Teams
How should development teams adopt AI without sacrificing code quality or collaboration? In this Talking Drupal Cafe, Stephen Cross is joined by Mike Miles and Jim Birch to discuss practical strategies for integrating AI into Drupal development teams. They explore AI coding assistants, team policies, code review, agent workflows, governance, and real-world lessons from using tools like Claude Code and GitHub Copilot in production environments.
For show notes visit: https://www.talkingDrupal.com/cafe020
Topics
- Why AI Matters Now
- Team Introductions
- From Experiments to Workflows
- Standards and Guardrails
- Skills and Automation Examples
- Taming Verbose AI Code
- Adoption and Tool Choices
- Governance and Training
- Measuring Productivity Gains
- Keeping Up Without FOMO
- AI for Editors and Site Features
- Red Teaming and AI Security
Jim Birch
Jim Birch is Director of Engineering and AI Practice Lead at Kanopi Studios, where he leads engineering teams and oversees the company's responsible adoption of AI. Jim is also a Drupal CMS committer, and Recipes Initiative Coordinator, and is a Google Cloud Certified Generative AI Leader.
Michael Miles
Mike Miles is a technical leader and speaker with more than 20 years of experience in web engineering, open-source development, and digital platform delivery. As the Director of Web Development at MIT Sloan, he leads the team responsible for the development, maintenance, and growth of the school's public digital properties.
Mike regularly speaks at technical conferences on topics including modern web development, Drupal, technical leadership, testing, delivery practices, and practical AI adoption. He is also one of the organizers of New England Drupal Camp.
Stephen Cross
Stephen Cross has been a Drupal developer for over 20 years and founded Talking Drupal in 2013. As founder of Second Signal Media, he combines his passion for open source and media production to share conversations that help the Drupal community learn and grow.
Guests
Michael Miles - mikemiles86
Jim Birch - thejimbirch
Stephen Cross - stephencross
Resources
Courses https://anthropic.skilljar.com/ https://academy.openai.com/pages/courses
Skills https://kanopi.github.io/cms-cultivator/ https://kanopi.github.io/delivery-record/
03 Aug 2026 4:05am GMT