On this page
You've just heard that WordPress 7.0 "comes with built-in AI". And you're picturing it: from now on the site writes its own posts, optimizes itself, runs itself. All you have to do is click Update.
Let me be blunt: that isn't what happened.
WordPress 7.0 didn't put intelligence into core. It put a socket into core. There is no AI model inside that release. No model, no "brain", nothing that runs at all unless you bring someone else's API key, plug it in and pay for it yourself.
That's a very smart architectural decision. But it also means all of the cost, the security risk and the content quality land on your side of the table. And there's one number from the same period that almost nobody mentions next to the AI headlines. It says more than the new features do.
What happened, and when
On May 20, 2026, WordPress 7.0 "Armstrong" shipped. It was the first major release of 2026, with more than 875 contributors (over 200 of them first-timers) and more than 420 enhancements and fixes (WordPress.org).
The AI pieces of the release, according to the official announcement:
- An AI Client in core: a standard layer for WordPress to talk to generative AI models.
- The Abilities API: a way for AI to take actions inside WordPress, not just generate text.
- A Connectors screen: where administrators connect external AI providers.
- Client-Side Abilities: a JavaScript version of the Abilities API, plus a Command Palette (⌘K or Ctrl+K).
- An official AI plugin (separate, not in core) that does the concrete jobs: generating and editing images, suggesting titles, summarizing, writing alt text.
And the feature the whole community was waiting for, Google Docs-style real-time collaborative editing, was pulled from 7.0 at the last minute over performance concerns and data-conflict bugs. It moved to the 7.1 cycle.
Then on July 9, 2026, WordPress 7.0.1 arrived: a pure maintenance release with 31 bugs fixed across Core and the Block Editor, led by Aaron Jorbin, Brian Haas, Carlos Bravo and Estela Rueda. The next major release, WordPress 7.1, is scheduled for August 19, 2026, at WordCamp US (WordPress.org).
That's the real timeline. Now for the more interesting part.
WordPress isn't selling you AI. It's selling you a socket.
This is the detail that decides everything, and it lives in the technical documentation, not in the headlines.
The Connectors screen launched with three default providers: Anthropic, Google and OpenAI (Make WordPress Core, March 18, 2026). WordPress core doesn't take sides among them. It only defines how the wiring works.
What does that mean for a business owner?
It means you upgrade to 7.0 and nothing happens on its own. No AI runs. To use it, you open an account with OpenAI, Google or Anthropic, generate an API key, paste it in, and from then on every time the AI does any work, you get billed, per token, directly by the provider, not through WordPress.
Get this right: WordPress 7.0 doesn't give you free AI. It standardizes how your website rents AI from a third party. The bill, the output quality and the data responsibility are still yours. Only the wiring comes pre-installed.
I think this is the right call. If WordPress had baked a fixed model into core, it would have locked roughly 40% of the web into a single vendor, and it would have been obsolete within six months. Building neutral infrastructure is the only sane option.
But "architecturally right" is not the same as "safe to deploy". And this is where I want you to slow down the most.
What almost nobody noticed: API keys sitting in plain text in the database
WordPress can load an API key three ways, in order of priority: environment variable → PHP constant in wp-config.php → a setting stored in the database.
If you paste the key into the field in the admin screen, it takes the third route. And the official technical documentation says, verbatim: "API keys stored in the database are not encrypted but are masked in the user interface." Encryption is "being considered in a separate ticket: #64789" (Make WordPress Core).
The same documentation admits one more thing outright: because the key is a site-wide setting, every plugin on the site can read it.
Translate that into business terms:
- One leaked database backup = your API key exposed, intact.
- One cheap plugin with a SQL injection hole = an attacker reads the
wp_optionstable straight off and takes the key. - One staging environment someone forgot to password-protect = a stranger spending money on your OpenAI account.
This isn't a secret flaw. It's written publicly in the developer documentation. The problem is that almost no website owner reads developer documentation. They see an empty field labelled "API key" and paste.
The fix is simple: ask your technical team to load the key via an environment variable or a constant in wp-config.php, not through the admin screen. Same feature, same experience, but the key doesn't live in the database, which is exactly the thing that gets backed up, copied and carried around everywhere.
The real game-changer doesn't have "AI" in its name
If I could keep only one line from the 7.0 release notes, I wouldn't pick the AI Client. I'd pick the Abilities API.
The AI Client only helps WordPress talk to a model. The Abilities API does something quite different: it lets the site declare the abilities it can perform (navigating the admin, inserting content blocks, running commands) in one consistent standard that software can call.
Sounds dry. The implications aren't.
For twenty years, WordPress has been designed for humans clicking a mouse. The Abilities API is the first time it has been designed for software in control. Your website is no longer just a place for people to read. It becomes something an AI agent can operate.
And that's exactly where the team is heading. In the notes from the July 8, 2026 meeting, contributors stressed that "abilities should be viewed as fundamental functional units of WordPress, separate from the transport layer". In other words, they don't just serve AI; they're a new interface layer for the whole platform. The scope for 7.1 focuses on read abilities first, not yet on administration (Make WordPress AI).
That's the news worth watching. Over the next two to three years, "can AI read and operate your website correctly?" will become a real business question, no different from "is your website on Google?" fifteen years ago. We've written about this direction in depth in SEO for businesses in the AI era.
The 41.9% figure: what AI in core can't fix
Now for the part that tech coverage of WordPress 7.0 usually skips.
Over exactly the period in which WordPress poured its energy into putting AI in core, its market share fell for six months in a row. According to W3Techs data, it went from 43.20% (December 2025) to 41.90% (May 27, 2026): 1.3 percentage points lost in half a year, double the decline of all of 2025 combined (0.60 points) (Search Engine Journal).
Over the same stretch, where did that share go? Shopify +0.20 points, Wix +0.10, Squarespace +0.10.
Look closely at that list. None of those platforms won because they had better AI. They won for a very old reason: business owners want something that works right away, needs no maintenance, doesn't break from plugin conflicts and doesn't require hiring someone to babysit it.
That's the blind spot. AI in core doesn't address the reason people leave WordPress. Nobody abandons WordPress because it lacks a socket for a language model. They leave because they're tired: of 40 plugins, of updates that break the layout, of slow pages, of a security incident every year.
And to be fair: Connectors just added a new risk to that list, a spot in the database holding a key that leads straight to an account that can bill you.
I'm not saying WordPress is heading the wrong way. The Abilities API is a smart long-term bet. But if you're choosing a platform for your business in 2026, "WordPress has AI now" is not a reason to pick it or to avoid it. The real reasons are still the boring ones: who runs it, who's accountable when it goes down, and whether the site is fast.
So what should you do with this?
Concretely, in order:
- Update to 7.0.1, but not for the AI. Update for the 31 bugs that were fixed. And test it on staging first, because 7.0 changes the admin interface significantly.
- Don't turn on Connectors without a clear purpose. An unused API key is still an API key that can leak. No need, no plug.
- If you do turn it on: load the key via environment variable or
wp-config.php, not through the admin screen. That's the one sentence you need to forward to your technical team. - Set a spending limit directly on your AI provider account. It's the last line of defense if the key gets abused, and it's out of WordPress's reach.
- Ask your technical team exactly three questions: Where is the API key stored? Who on this site can read it? If our database backup leaked tomorrow, what would happen?
If the answer to the first question is "in the settings", you have work to do this week.
Version 7.0 is a real milestone, just not the one the headlines describe. WordPress didn't just get smarter. It got easier for machines to operate, and it opened one more door that you have to lock yourself.
Want someone to review your WordPress site before you switch on anything AI-related? Talk to us. It takes fifteen minutes, and it's far cheaper than finding the problem after it has happened.
Sources
- WordPress 7.0 "Armstrong" — WordPress.org News (May 20, 2026)
- Introducing the Connectors API in WordPress 7.0 — Make WordPress Core (March 18, 2026)
- WordPress 7.0.1 Maintenance Release — WordPress.org News (July 9, 2026)
- AI Contributor Weekly Summary — Make WordPress AI (July 8, 2026)
- WordPress Market Share Declines For Six Months In A Row — Search Engine Journal
- WordPress 7.0 Launches With Native AI Integration — Search Engine Journal
- Security audit for API key storage on the Connectors screen — WordPress Trac #64789

