The Demo Is Over. Now Drupal AI Has to Become a Product.
After Rotterdam, one part of Drupal's AI story is no longer theoretical. The Northmoor University demo brought AI search, content review, translation, editing and externally connected assistants together on the same Drupal site. That made a collection of modules feel closer to a product experience, but it also exposed the next question: whether organisations can depend on the path between those pieces in production.
The stack does not yet sit at one level of maturity. Drupal AI 1.5 and Canvas are stable and covered by Drupal's security advisory policy. Context Control Center is a release candidate, while Tool API and MCP Server remain in beta. Rotterdam showed that these parts can work together. Production teams now have to decide which combinations are mature enough to trust, govern and support.
Permissions, human review and traceability are central to that decision. The demo drafts changes rather than publishing them, leaving a person to review what the AI proposes. Tool API brings access checking into executable capabilities, while MCP can expose Drupal tools to assistants outside the site. Context Control Center moves instructions and organisational knowledge toward managed, reviewed material. Taken together, those pieces point toward a production requirement that goes beyond capability: teams need to know what an agent may read, what it may change, which tools it may invoke, what context it received and who remains accountable for the result.
Provider choice and the connection between Tool API, MCP and Canvas make the remaining maturity gap visible. Drupal's provider abstraction supports different commercial and locally operated models, but workflows still need to remain testable as model behaviour, tool calling and context limits change. The Drupal AI Initiative's follow-up also draws a clear line between what Rotterdam demonstrated and what is available today: the simplified MCP approach shown on stage remains a prototype. Canvas Tools, which lets agents manipulate Canvas through Tool API, is likewise still beta and is not covered by the security advisory policy.
That does not make Drupal AI simply ready or not ready for production. Different parts of the stack already support different kinds of real use, with different levels of risk. Rotterdam instead changes what Drupal AI now has to prove: that permissions remain enforceable, context can be governed, costs and activity can be traced, providers can change without losing control, and interfaces can survive upgrades. Productisation does not mean closing the ecosystem or putting everything inside one package. It means reaching the point where an organisation can understand what an AI system will be allowed to do before deployment, and explain what it actually did afterwards.
Follow The DropTimes on LinkedIn, X, Bluesky, and Facebook, or join #thedroptimes on Drupal Slack.
Allen Jason wrote and curated this issue of Editor’s Pick.
