Why Drupal sites get read and cited by AI
AI crawlers already fetch product pages during live conversations, but citations stay rare. Drupal sites cited by AI need one fact in fields, then the same value on the page, in JSON-LD, in feeds and through JSON:API or MCP tools.
Maciej Lukianski walks through what fetchers need, which Drupal modules cover Markdown, llms.txt and MCP Server today, and where configuration still decides whether a bot can quote your catalogue.
Intelligent Layouts: Drupal Canvas AI and the Context Layer
Optimizing Drupal Core CI
At DrupalCon Vienna, Tim Lehnen presented on the main costs for running Drupal.org. Around 50% of the total cost of running drupal.org, or approximately $1.5m, is infrastructure costs. A significant slice of infrastructure costs comes from drupal.org's self-hosted GitLab, and in turn much of that cost is due to GitLab CI for Drupal core and contributed modules.
Figure 1: Drupal Engineering activities compared to the various funding sources
Drupal core is the single biggest project in terms of CI minutes, both due to the sheer number of tests as well as the level of activity in Drupal core issues, with hundreds of commits per month and activity on thousands of issues and Merge Requests ("MRs").
Top Drupal Newsletter Modules and a Mailchimp Integration Guide
Newsletters are meant to keep audiences connected in a consistent way, building familiarity and trust. They carry updates, stories, and ideas straight into inboxes. It’s a format that rewards consistency over noise, and clarity over clever tricks. A good newsletter feels less like marketing and more like a friendly letter that arrives just when you need it.
AI at DrupalCon Rotterdam

Written by Duncan Worrell (dunx)
DrupalCon Rotterdam is almost here. Alongside two dedicated AI summits and the main conference keynote, the program is stacked with high-value AI content for developers, strategists, and leaders alike. Whether you're looking to push agentic workflows, scale digital governance, streamline content operations, or keep your AI integrations trustworthy, here is a complete breakdown of the top AI sessions to help you optimize your schedule.
Full schedule at https://events.drupal.org/rotterdam2026/schedule
Tickets at https://events.drupal.org/rotterdam2026/registration-information
All session times are local CEST.
SummitsIn addition to the main DrupalCon event, there are two AI-specific summits being held catering for two very different audiences.
Enterprise Drupal AI Summit
An executive-focused event for CXOs, Heads of Digital, and enterprise leaders connecting with curated Drupal AI partners. Hosted on the historic former ocean liner, SS Rotterdam.
Date & Time: All day Monday, 28 September
Event details here: https://summit.enterprisedrupal.eu/schedule.html
AI Dev Summit
Getting Drupal developers up to speed on AI coding tools, AI in PHP/Symfony/Drupal frameworks, Canvas, and Drupal CMS innovations.
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013
drupalDate: 2026-September-16Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Third-party librariesAffected versions: >=10.5.0 <10.6.17 || >=11.0.0 <11.3.17 || >=11.4.0 <11.4.7Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal.
Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisory:
Solution:Install the latest version:
Drupal 11
Everybody Orchestrates. Most Do It by Hand.
Every month I do my agency's billing by hand: export timesheets from one system, create invoices in another, merge, email, file, upload to the accountant. I maintain ECA. Elsewhere, a multi-agency project runs from an Excel sheet nobody can keep current, because the spreadsheet is the only place people see everything and feel in control. Everybody orchestrates, most by hand, and not for lack of tools. ECA, Maestro, FlowDrop, Tool API, AI Integration - ECA 1.0.0 and the Orchestration module with Activepieces, soon n8n, could run my billing end to end today. But the builder opens five UIs and, worse, has to decide which engine runs which step. No user can make that decision. The fix is one UI: every component of every participating system on one canvas, engine routing done by the platform. The Modeler API, the Workflow Modeler, Tool API's typed contract and Post 6's shared vocabulary are that architecture. Missing: a composite model owner, a dispatcher, the cross-system data contract. Let's build them. In Drupal.
How to eliminate manual credential sharing in Drupal integrations with a Vault service
Credentials still travel by email and by Slack on projects that are otherwise carefully built. Every integration with an external service needs them, and forwarding them from one party to the next is so routine that the risk rarely gets questioned. That habit is avoidable, and avoiding it changes who holds the secrets and who never has to see them.
The habit of sharing passwords over email or SlackReceiving a password in plain text over email or Slack is a common occurrence on any Drupal project. It happens because every integration with an external service, whether a payment gateway, a CRM, or a third-party API, requires access credentials. Username and password pairs, tokens, private URLs, and other sensitive data that at some point need to travel from one place to another.
These credentials should never go into a code repository or into Drupal's YAML configuration files. The exposure risk is too high. The most common alternative, however, does not solve the underlying problem.
The burden of provisioning credentials in a projectThe most widespread practice is to store secrets in a file outside the webroot, or to define them as environment variables accessible only to PHP. This works, but carries an operational cost that becomes apparent as soon as a password needs to change: those files must be edited by hand, and if environment variables are used, reloading Apache or Nginx may be required.
The deeper problem is the…
Same rules, every suggestion: the Context Control Center and your AI Automators
Drupal 12 or Drupal 11 — upgrade now or wait?
Drupal architecture: monolithic, decoupled or hybrid
Choosing between monolithic, decoupled, and hybrid Drupal should start with publishing cost - not a frontend framework preference.
Drupal architecture determines how many systems your team must maintain to deliver server-rendered HTML that readers and AI crawlers can use on the first response. Here is how to compare the three options by preview, metadata, cache invalidation, and operating work.
Joomla Migration in 2026: Where to Go, What It Costs, and What Breaks
September 2026 Drupal for Nonprofits Chat
Join us THURSDAY, September 17 at 1pm ET / 10am PT, for our regularly scheduled call to chat about all things Drupal and nonprofits. (Convert to your local time zone.)
We don't have anything specific on the agenda this month, so we'll have plenty of time to discuss anything that's on our minds at the intersection of Drupal and nonprofits. Got something specific you want to talk about? Feel free to share ahead of time in our collaborative Google document at https://nten.org/drupal/notes!
All nonprofit Drupal devs and users, regardless of experience level, are always welcome on this call.
This free call is sponsored by NTEN.org and open to everyone.
Information on joining the meeting can be found in our collaborative Google document.
JSON-LD in Drupal: how to generate structured data from fields with Schema.org Metatag
The safest way to add JSON-LD to Drupal is to map Schema.org properties to existing content fields with Metatag and Schema.org Metatag.
JSON-LD in Drupal should come from the same field model that supplies the visible page - not from hand-written scripts that drift when prices or availability change. Here is how to map tokens, export config, validate rendered pages, and catch missing bundles in CI.
Drupal Code Search now index recipes
Made it easier to get a list of projects that are included in a particular recipe. It's thanks to the sponsorship of Vardot, and previously Palantir.net that I'm able to spend time on tooling for the community. Many thanks to them.
Code search:
theodore September 15, 2026Wondering why Drupal needs another page builder? Here's what I learned installing Drupal Canvas, exposing my SDCs, and writing React right in the browser.
Architecting a Headless RAG Engine with Drupal 11

Drupal 11 is evolving into something far more powerful than a traditional Content Management System. For enterprise organizations, it is quickly becoming the foundational vector engine for secure, sovereign AI.
As organizations move beyond the hype of basic generative AI, the limitations of standard API wrappers become clear. Bolting a conversational UI onto a monolithic frontend, and blindly passing proprietary node data to public third-party models, introduces unpredictable latency, unmanageable token costs, and critical data compliance risks.
The Core Architectural DilemmaWhen an organization attempts to integrate AI without a solid architectural foundation, the implementation typically fails through three specific avenues:
Sitewide governance for AI answers: the Context Control Center and your chatbot
Acquia rebrands around content and Drupal
Today Acquia launched a new brand, and my favorite part is the updated logo. Right under the Acquia name, it now says "Powered by Drupal".
Drupal has always been at the core of Acquia, but for the past 5 years it was less visible in how we described ourselves. Now it's front and center again.
But that is not the main reason for the rebrand. The bigger reason for the rebrand is to help people see what Acquia has become. Our products have evolved faster than awareness of them.
The new brand leads with content instead of digital experiences, and the homepage calls Acquia an "agentic content platform" rather than a "digital experience platform".
Acquia Source is our new command center, bringing content management, digital asset management, and web governance into one workspace. Acquia AI coordinates agent work across those tools.
For agents to work safely across these tools, they need content they can trust and clear rules for using it. Somebody still has to decide what is approved, who can use it, and where it can go. I wrote about that in AI and the great CMS unbundling, and the new brand puts that idea at the center of our story.
Drupal is well suited for that job. Structured content, granular permissions, workflows, and revision history are the things agents need to work safely, and Drupal has refined them for years.