Every trend below is grounded in something you can check today: an announcement, a spec, a dataset or a law that already exists in 2025 or 2026. For each one you get what is happening, the evidence with its source, and what to do about it before 2027. Where the evidence is thin, we say so.
The angle is practical. We build Diggama, a headless CMS that AI coding agents (Claude Code, Codex, Cursor and others) reach over MCP, so we watch these shifts from the content side: who edits the site, how agents reach the content, and what survives the next rebuild.
What are the main web development and CMS trends for 2027?
The short version: code becomes cheap, and everything around the code (content, review, access rules, compliance) becomes the work. Ten trends, each with its strongest piece of evidence and the first action to take:
| # | Trend for 2027 | Strongest 2025-2026 evidence | Do this now |
|---|---|---|---|
| 1 | Coding agents write the code; maintenance is the bottleneck | Agent use at work rose from 31% to 59% in a year (Stack Overflow) | Move copy out of components |
| 2 | Page builders turn into code generators | Webflow App Gen, Framer Workshop, Figma buys Payload | Decide who owns code vs content |
| 3 | MCP is the standard interface to business systems | MCP donated to the Linux Foundation, 10,000+ public servers | Pick tools with a scoped MCP server |
| 4 | Agents edit content, humans approve | 63% rarely or never let agents run on autopilot | Draft-only tokens, dry runs, publish rights for people |
| 5 | Pages are written for LLM readers | Users click links on 8% of searches with an AI summary vs 15% without (Pew) | Answer-first sections, sourced facts |
| 6 | AI crawling gets priced or blocked | Cloudflare default-blocked AI crawlers (2025), then split search from training (2026) | Write an explicit robots.txt policy |
| 7 | Agents visit sites and act on them | WebMCP in a Chrome origin trial (Chrome 149) | Plain forms, semantic HTML |
| 8 | Frameworks consolidate onto edge platforms | Cloudflare acquires Astro; Next.js ships a stable Adapter API | Keep the build portable |
| 9 | The content model is the asset | Agents regenerate code; CMS schemas are exposed over MCP | Model content as typed fields |
| 10 | Accessibility is enforced by law | European Accessibility Act applies since 28 June 2025 | Audit against WCAG 2.1 AA or 2.2 AA |
1. Will coding agents build most websites in 2027?
For sites built by developers, very likely: agent use at work nearly doubled between 2025 and 2026. The bottleneck then moves from writing code to maintaining it: who changes the content, who reviews the diff, and who still understands the project six months later.
What is happening. In the 2025 Stack Overflow Developer Survey (more than 49,000 respondents), 84% of developers used or planned to use AI tools, but only 31% used AI agents at work at any frequency. By Stack Overflow’s April 2026 pulse survey of 1,100 developers, agent use had reached 59%, and daily use went from 14% to 37%. The coding agents most used in the previous six months were GitHub Copilot (61%), Claude Code (51%), OpenAI Codex (20%) and Cursor (20%). Anthropic reported in December 2025 that Claude Code had passed $1 billion in run-rate revenue.
The catch. Trust has not kept pace. In the 2025 survey, 45.7% of developers distrusted the accuracy of AI output and 66% named “AI solutions that are almost right, but not quite” as a frustration. On a website, “almost right” means hardcoded copy, duplicated components and no editorial workflow: the site works on launch day and becomes a support queue in month two (why AI-built websites need a CMS).
What to do now. Treat generated code like code from a fast junior developer: give it rules, review it, and keep content out of it. Put the rules in an AGENTS.md file at the root of the repository (template here), and make “no copy in components” the first one. Most agents read that file as is; two need a step:
| Agent | Reads AGENTS.md | What to do |
|---|---|---|
| OpenAI Codex | Yes | Nothing (docs) |
| Cursor | Yes | Nothing; .cursor/rules adds scoped rules (docs) |
| GitHub Copilot in VS Code | Yes, on by default | Nothing (docs) |
| Claude Code | Only when there is no CLAUDE.md | Start CLAUDE.md with @AGENTS.md to read both (docs) |
| Gemini CLI | Not by default | Add it to context.fileName in settings.json (docs) |
2. Are page builders like Webflow and Framer declining?
Page builders are not disappearing; they are becoming AI code generators themselves. What declines is their pull on developer-led teams, who can now get a custom coded site from an agent and want the code in their own repository.
Evidence. Webflow announced App Gen at Webflow Conf in September 2025: a prompt generates an app on the site’s design system and deploys it to Webflow Cloud. Framer launched Workshop in May 2025 to generate components from a description. And in June 2025, Figma bought Payload, a code-first open source CMS, to close the gap where “designers create in Figma, then devs recreate in code, then content teams struggle to maintain it all” (Payload announcement).
The visual tools are bringing code generation inside. Their strength is real: a design-led team without a developer still ships faster in Webflow or Framer than with a terminal, and marketers get a visual editor out of the box.
What to do now. Decide explicitly. With a developer who wants control of code and hosting, the coded stack (an AI coding agent such as Claude Code, Codex or Cursor, a framework, a headless CMS) fits. If nobody will ever open a terminal or an AI editor, a visual builder is the safer choice. Our Webflow vs Framer vs AI coding comparison runs the three-year costs, and the Webflow migration guide covers the move.
3. Will MCP become the standard way AI connects to a CMS?
Yes. The Model Context Protocol is already the default way AI tools connect to business systems, and in 2027 a CMS without an MCP server will need a reason. What will separate products is how tightly each server scopes access, not whether one exists.
Evidence. Anthropic donated MCP to the Agentic AI Foundation, a Linux Foundation fund co-founded with Block and OpenAI, on 9 December 2025. At that point Anthropic counted more than 10,000 active public MCP servers and 97 million monthly SDK downloads, with MCP adopted by ChatGPT, Cursor, Gemini, Microsoft Copilot and VS Code. The 2025-11-25 specification improved OAuth support.
The CMS market followed. By October 2026, Sanity, Contentful, Storyblok, Prismic and Hygraph run hosted MCP servers, and Strapi and Directus ship one in the core. Our headless CMS comparison has the details for each.
Why it matters for content. With MCP, an agent reads the real content model instead of guessing field names, and it can draft content where editors will review it. Diggama’s MCP server at https://api.diggama.com/mcp builds its tool list from the token: a view-only token gets four read tools and no write tool at all. It authenticates with a project token sent as a Bearer header and does not offer OAuth yet. That works in the coding agents that let you set a header on a remote MCP server, including Claude Code, Codex (its CLI, IDE extension and the ChatGPT desktop app share one config, per OpenAI), Cursor, Gemini CLI and GitHub Copilot in VS Code. Chat apps are behind: ChatGPT on the web connects only with OAuth or no auth (OpenAI), and claude.ai custom connectors rely on OAuth, with fixed request headers in a beta limited to some organizations (Anthropic), so use a coding agent with Diggama for now (Claude Desktop can also reach it through the third-party mcp-remote bridge). The headless CMS MCP server guide has the setup for each agent.
What to do now. When you choose a CMS, check four things: whether a read-only connection hides the write tools, whether writes can stay drafts, whether destructive actions can be withheld, and whether you can preview a write before it happens.
4. How will AI agents edit website content safely?
Agents will draft, translate and fix content in the CMS, and people will approve what goes live. The pattern that is winning is “agent writes drafts, human publishes”, enforced by permissions rather than by trusting the model to behave.
Evidence from practice. In Stack Overflow’s April 2026 pulse survey, 63% of respondents rarely or never let agents run on autopilot, and 60% block agents from making unapproved system changes. CMS vendors encode the same caution: Hygraph’s MCP server does not support delete or unpublish, Prismic’s writes into releases you publish separately, and Diggama’s MCP server accepts dry_run on every create and update, which shows the resulting record or a field-by-field diff without writing anything.
Evidence from regulation. Article 50 of the EU AI Act applies from 2 August 2026. Text generated by AI and published to inform the public on matters of public interest must be disclosed as such, unless it went through human review or editorial control and a person or company holds editorial responsibility. The review must be substantive, not a cursory approval. Most marketing copy is not “public interest” text, but a recorded human approval step is becoming a compliance feature.
What to do now. Separate the abilities. In Diggama, a token’s abilities are set per blueprint (view, preview, create, update, delete, publish, see authentication). Give the agent’s MCP connection view, preview, create and update on the content types it works on (in Configuration › Connect to AI, the “Read & write” preset grants exactly this on every type; “Customise per content type” narrows it), and keep publish and delete for people. Over MCP, records the agent creates stay drafts, because setting published_at needs publish. Edits are different: Diggama keeps no separate draft copy of a published record, so an update to a published post is live in the API as soon as it is saved, and it fires your workflows (a rebuild hook, for example). That is why you ask for the diff before any bulk change:
Using the Diggama MCP server, call describe_blueprint for "posts", then find every post whose excerpt is empty or longer than 160 characters (use get_resource to read each post's full content). For each one, propose a new excerpt of 120 to 155 characters written from the post's content, and show me the change with update_resource, mode "merge" and dry_run: true. Group the results into drafts and published posts, because an update to a published post goes live as soon as it is saved. Do not write anything until I approve the list, then apply the approved changes one post at a time and report each one.5. How do you write a website for LLMs and AI search in 2027?
Write each page so a language model can lift one section and quote it correctly: one question per section, the answer in the first sentence or two, sourced numbers, comparisons in tables, and server-rendered HTML. This is often called GEO (generative engine optimization), and in practice it is disciplined SEO.
What is happening. Answers increasingly happen before the click. A Pew Research Center study of 900 US adults’ browsing in March 2025 found that users clicked a traditional result on 8% of searches that showed an AI summary, against 15% when there was none, and clicked a link inside the summary on 1% of visits. If fewer people click, being the source the answer quotes matters more.
What helps, and what is unproven.
- Answer-first structure. A section that opens with a self-contained answer is easy to extract and quote.
- Structured data that matches the page. Google’s guidance on AI features says there is “no special schema.org structured data that you need to add” and that you do not need “new machine readable files, AI text files, or markup” to appear in AI Overviews or AI Mode. Standard SEO, and structured data that matches the visible text, are what count.
- llms.txt. Proposed by Jeremy Howard in September 2024, it gives models a Markdown map of a site. Google’s John Mueller said in June 2025 that “no AI system currently uses llms.txt”. It still helps coding agents that read documentation, and it costs little.
- Markdown versions of pages. Cloudflare launched Markdown for Agents in February 2026: when a client sends
Accept: text/markdown, Cloudflare converts the HTML at the edge. On Cloudflare’s own example post, that cut 16,180 tokens of HTML to 3,150 of Markdown, and the post notes that coding agents such as Claude Code and OpenCode already request Markdown. diggama.com serves a Markdown twin of every guide (replace the trailing slash with.md, as in/guides/web-and-cms-trends-2027.md) and lists them in/llms.txt.
What to do now. Audit your top pages for answer-first structure before you add any new file format. A prompt that does the first pass:
Audit the pages in src/pages/ for AI search readiness. For each page, list: (1) H2 headings that are not phrased as the question a visitor would search, (2) sections whose first two sentences do not directly answer that heading, (3) numbers or claims without a source link, (4) content that only appears after client-side JavaScript runs, (5) JSON-LD that does not match the visible text. Content that lives in Diggama (see AGENTS.md for the blueprints) must be fixed in the CMS, not in the components: list those changes per resource instead of editing code.6. Should you block AI crawlers or charge them?
You need an explicit policy, because the defaults keep changing under you: Cloudflare blocked AI crawlers by default on new domains in July 2025, then replaced that default with presets that separate search from training in September 2026. Decide separately for search, AI answers and model training.
Evidence. On 1 July 2025, Cloudflare, which handles about 20% of the web, made AI crawler blocking the default for new domains and launched pay per crawl in private beta, which answers crawlers with HTTP 402 Payment Required. Its data explains why: in July 2025, Anthropic’s crawlers made about 38,000 requests for each visitor referred back, OpenAI’s about 1,091 and Perplexity’s about 195 (Cloudflare, August 2025). A year later, Cloudflare reported that training made up 52% of crawler requests, up from 22% in spring 2025, while Google still sent about 88% of referral traffic.
The vocabulary is getting more precise. Cloudflare’s Content Signals Policy (September 2025) adds three robots.txt signals: search, ai-input (use in AI answers) and ai-train. On 15 September 2026, Cloudflare changed its defaults again: new domains now pick one of two presets. Ad-supported sites get “Disallow AI Training”, which lets search crawlers such as Googlebot, Bingbot and Applebot keep crawling while refusing training; other sites get training allowed. Cloudflare publishes the preference in robots.txt and blocks crawlers that ignore it. At the IETF, the AI Preferences working group is drafting a standard vocabulary for the same choices.
What to do now. Write the policy down in robots.txt instead of relying on a dashboard default. This file refuses training, stays in search and AI answers, and names each training crawler the vendors document (OpenAI, Anthropic, Google-Extended):
# Northwind Studio crawler policy
# Search and AI answers: yes. Model training: no.
User-agent: *
Content-Signal: search=yes, ai-input=yes, ai-train=no
Allow: /
# OpenAI training crawler (OAI-SearchBot, used for ChatGPT search, stays allowed)
User-agent: GPTBot
Disallow: /
# Anthropic training crawler (Claude-SearchBot and Claude-User stay allowed)
User-agent: ClaudeBot
Disallow: /
# Gemini training and grounding (does not affect Google Search)
User-agent: Google-Extended
Disallow: /
# Apple model training (Applebot, used for search, stays allowed)
User-agent: Applebot-Extended
Disallow: /
Sitemap: https://www.northwind-studio.example/sitemap-index.xml
Three caveats. Google documents that Google-Extended also controls grounding in Gemini apps, so blocking it can remove you from Gemini answers. OpenAI notes that robots.txt rules may not apply to ChatGPT-User, because those fetches are made at a user’s request. And if your site sits behind Cloudflare with its managed robots.txt turned on, Cloudflare prepends its own rules to your file, so open the served /robots.txt after deploying and check that the two do not contradict each other.
7. Will AI agents visit websites and fill in forms?
Yes, and browsers are building a standard for it. In 2027, part of your traffic will be agents acting for a person: comparing offers, booking, filling in a contact form. Sites that expose clear forms and actions will work for them; sites that hide everything behind custom JavaScript will not.
Evidence. Engineers from Google and Microsoft edit the WebMCP draft in the W3C Web Machine Learning Community Group; it is a community draft, not a W3C standard. Chrome opened an early preview in February 2026 with two APIs: a declarative one for actions defined in HTML forms and an imperative one in JavaScript. In June 2026, Chrome 149 opened a WebMCP origin trial. Cloudflare’s July 2026 report states that more than half of Internet traffic is now non-human. WebMCP is still experimental, so the safe bet should not depend on it.
What to do now. Use native <form> elements with real labels, name attributes and server-side validation. They work for screen readers, for today’s browser agents and for the declarative side of WebMCP. Store what arrives somewhere your team reads. On the Northwind Studio demo, a server endpoint writes each message to a read-only contact-submissions blueprint with a token that can only create; the build a website with AI tutorial builds it.
8. Which frameworks and hosting platforms will matter in 2027?
Fewer, larger platforms will own the main frameworks, and deployment will become more portable between them. Content sites will run as static or edge-rendered pages on global networks, with framework teams funded by hosting companies.
Evidence. The consolidation is documented:
| Date | Event | Source |
|---|---|---|
| June 2025 | Figma acquires Payload (CMS) | Payload |
| July 2025 | Vercel acquires NuxtLabs (Nuxt, Nitro) | RedMonk |
| December 2025 | Anthropic acquires Bun (JavaScript runtime) | Anthropic |
| January 2026 | Cloudflare acquires the Astro team; Astro stays MIT-licensed | Cloudflare |
| March 2026 | Next.js 16.2 ships a stable Adapter API for any host | Next.js |
| June 2026 | Astro 7 adds coding-agent detection and a background dev server | Astro |
Each acquirer promised to keep the project open source. Cloudflare states you can still “deploy Astro to any platform or cloud”, and Vercel’s own Next.js adapter uses the same public Adapter API as everyone else, with adapters for Netlify, Cloudflare and AWS announced as in development at launch. Frameworks are also adapting to agents: Astro 7 detects when it runs inside an AI agent and runs the dev server as a managed background process, so the agent does not hang or start duplicates.
What to do now. Keep the build portable: content from an API, secrets in environment variables, no platform-only features in your page code unless they earn it. Our tutorials use Astro and Next.js on Cloudflare (Astro, Next.js), but the same code moves to another host with an adapter change.
9. What is the future of the headless CMS?
The headless CMS becomes the system of record that agents and people share: the content model defines what the site says, editors change it in a dashboard, the frontend reads it through an API, and agents read and draft it through MCP. When code is regenerated on every redesign, the content model is the part that lasts.
Why the content model becomes the asset. If an agent can rebuild your frontend in a day, the frontend is not the hard part to replace; two years of posts, bios, case studies and translations are. Typed fields are also what make content usable by agents: they can be described as a schema, validated before a write and rendered by any framework. One blob of page HTML cannot. Frameworks are moving the same way: Astro 6 (March 2026) made live content collections stable, so a site can query a CMS at request time with typed results.
What it looks like in practice. Diggama’s MCP server exposes each blueprint through describe_blueprint, which returns its fields with a JSON Schema for the attributes, so your agent writes code and content against the real model. The same blueprint feeds the REST API at https://api.diggama.com/v2, and a Workflow with a “Send webhook” action can POST to your host’s deploy hook when a resource is created, updated or deleted (the body is only {"event": "resource_updated"} or similar, so the build fetches the content itself). A blueprint for Northwind Studio’s posts has a title (text), slug (slug), excerpt (text), cover (image) and content (rich text), with publication handled by published_at (publishing docs).
What to do now. Model content as types and fields, not as pages. Name fields for their meaning (hero_title, not text_1), keep presentation out of the content, and give each repeated thing (post, team member, case study) its own type. The content model generator drafts a first model from a description of your site, and Blueprints lists Diggama’s field types.
10. Is website accessibility now a legal requirement?
In the EU, for many consumer-facing services, yes: the European Accessibility Act has applied since 28 June 2025. In the United States, public-sector deadlines arrive in 2027. For any team building sites with AI, accessibility has to be a rule the agent follows, not a fix after launch.
Evidence. The European Accessibility Act (Directive 2019/882) covers services provided to consumers, such as e-commerce, banking, e-books and passenger transport, from 28 June 2025. Microenterprises providing services, fewer than 10 people with turnover or balance sheet of at most 2 million EUR, are exempt. Conformity is usually shown against the harmonised standard EN 301 549, whose web clause in version 3.2.1 incorporates WCAG 2.1 Level AA. In the US, the Department of Justice’s ADA Title II rule requires WCAG 2.1 AA for state and local governments; an interim final rule of 20 April 2026 moved the deadline to 26 April 2027 for larger entities and 26 April 2028 for smaller ones.
Where AI makes it worse or better. An agent copies whatever pattern it sees first, including a div with a click handler instead of a button. It is also good at mechanical fixes once told the rule. Content matters too: alt text, link text and heading order live in the CMS as much as in the code, so they need fields and editors who know they count.
What to do now. Put WCAG 2.2 AA rules in your AGENTS.md or your agent’s own instructions file (the template includes a section), add an alt field next to every image field in your content model, and run an automated check on every build. The website grader gives a quick first pass on a live URL.
Which 2027 predictions are less certain?
Three of the trends above depend on adoption that has not happened yet, and you should plan for them without betting on them.
- llms.txt. Widely published, unconfirmed as an input by any major AI search engine. Keep it, do not expect traffic from it.
- Paid crawling. Pay per crawl exists and Cloudflare keeps expanding the controls, but a market where most sites earn money from AI crawlers is not visible yet. Blocking training is the decision you can make today; charging for it is optional.
- WebMCP. In an origin trial, not a shipped standard. Accessible forms get you most of the benefit now.
How do you prepare your website for 2027? A checklist
Move content out of code, scope what agents can do, write down your crawler policy, keep the build portable and test accessibility on every build. Review the list each quarter.
Content and CMS
- No copy, image paths or SEO text hardcoded in components; all of it comes from the CMS.
- Content modeled as typed fields with meaningful names, one type per repeated thing.
- An
alttext field next to every image field, and editors who know it is required. - Drafts, preview and scheduled publishing work without a developer.
Agents and access
- An
AGENTS.mdwith rules for content, accessibility and deployment, kept in Git, and read by every agent you use (@AGENTS.mdinCLAUDE.mdfor Claude Code,context.fileNamefor Gemini CLI). - The CMS has an MCP server, and the agent’s connection starts read-only.
- Agents create drafts; publish and delete stay with people, and edits to published content need your approval first.
- Every bulk change starts with a dry run or a diff you approve.
- API tokens are scoped per content type and never reach the browser.
AI search and crawlers
- Each section of a key page answers its question in its first two sentences, with sourced numbers.
- Pages render as HTML on the server; key content does not need JavaScript to appear.
- A written
robots.txtpolicy for search, AI answers and training. - An
llms.txtand Markdown versions of key pages, if cheap to generate.
Platform and compliance
- The build runs on at least two hosts without code changes beyond the adapter.
- Forms are native HTML with labels, validated on the server, stored where the team reads them.
- An automated WCAG check runs on every build, and a manual audit runs before major launches.
- You know whether the European Accessibility Act applies to your services.
If an AI coding agent built your site with copy in the components, start with the first section. The build a website with AI tutorial builds Northwind Studio with Claude Code, Codex or Cursor, with its content in Diggama from day one, and Diggama’s pricing includes a three-month free trial with MCP on every plan.