AI in WordPress: AI Client, Connectors and the Abilities API Explained
AI in WordPress: AI Client, Connectors and the Abilities API Explained

As of October 2026, WordPress core includes the building blocks for AI but no AI service of its own. WordPress 6.9 added the Abilities API, a registry of actions a site can perform. WordPress 7.0 added an AI Client that lets plugins talk to generative AI models through one standard interface, and a Settings > Connectors screen where an administrator adds credentials for a provider such as Anthropic, Google or OpenAI. Nothing is sent to an AI company until someone configures a provider and a plugin or theme actually calls it.
That design matters for business owners. It means you decide whether AI touches your site at all, which provider is used and which plugins may use it. It also means the real AI features you will see, such as alt text drafts, excerpt and meta description suggestions or comment moderation, come from plugins built on top of core, including an official experimental plugin simply called "AI."
This guide explains each piece in plain terms, what data leaves your site and when, the plugin options, sensible uses and the risks to manage before you switch anything on.
Key Takeaways
- Core provides plumbing: the Abilities API (6.9), the AI Client (7.0) and the Connectors screen (7.0); no AI provider ships with WordPress.
- According to the merge proposal, WordPress "will not send prompts or data to any external service" without explicit configuration and explicit calling code.
- API keys entered on the Connectors screen are stored in the database unencrypted (masked in the interface) and are available to any installed plugin; environment variables or constants are an alternative.
- Practical AI features come from plugins, such as the official experimental "AI" plugin from WordPress.org, which needs a provider connector to work.
- Treat AI output as a draft: review it for accuracy, accessibility and brand voice, especially on health, legal and financial pages.
The building blocks in core
| Component | Added in | What it does | Who uses it |
|---|---|---|---|
| Abilities API | 6.9 (Dec 2025) | A standard registry of things a site can do, with typed inputs and outputs and permission checks | Plugin developers, AI tools and agents |
| AI Client | 7.0 (May 2026) | A provider-agnostic PHP API for sending prompts to AI models and receiving results | Plugin and theme developers |
| Connectors screen and API | 7.0 (May 2026) | Settings > Connectors, where admins add and manage provider credentials | Site administrators |
| Client-side abilities | 7.0 (May 2026) | A JavaScript counterpart with a built-in UI and Command Palette integration | Editors, via plugins |
| Abilities API updates | 7.1 (Aug 2026) | "A filterable execution lifecycle, custom validation, and shared discovery" | Developers |
Abilities API
The 6.9 release described the Abilities API as "a standardized registry" that is "opening doors for AI-powered workflows." Developers register an ability (for example "create a draft post" or "list recent orders") with a label, description, input and output schema and a permission callback. Because abilities are discoverable and typed, AI tools can find out what a site can do and call those actions safely, within the permissions of the user involved.
AI Client
The AI Client, introduced in a Make WordPress Core post in March 2026, is "a provider-agnostic PHP API that lets plugins send prompts to AI models and receive results through a consistent interface." A plugin can state a model preference, and WordPress routes the request to whatever compatible provider the site has configured. Developers can block specific prompts with a filter, and the client-side JavaScript API defaults to administrator-only access "to prevent untrusted users from accessing configured providers," according to the same post.
Connectors
The Connectors screen is where AI gets switched on. WordPress 7.0 features three connectors on that screen, for Anthropic, Google and OpenAI. Each provider is a separate plugin published by WordPress.org: AI Provider for Anthropic (60,000+ active installs as of October 2026), AI Provider for Google (50,000+) and AI Provider for OpenAI (50,000+). The Connectors API dev note explains how keys are found, in this order: an environment variable, a PHP constant, then the database (entered through the admin screen).
What data is sent, and when
The short answer: nothing, until three things are true. A provider plugin is installed, credentials are configured, and some code (a plugin, theme or custom function) sends a prompt. The AI Client merge proposal is explicit: the merge "does not ship any AI providers or automatically enable AI calls. Without explicit configuration and explicit calling code, WordPress will not send prompts or data to any external service."
Once AI is configured, what is sent depends entirely on the feature being used. A summarization feature sends the post text; an alt text feature sends the image; a comment moderation feature sends the comment. That content goes to the provider you configured, under that provider's terms. WordPress documentation does not set retention rules for third-party providers, so check your provider's data-use and retention policies, and your own privacy policy, before enabling features that process customer or patient data.
Two technical points worth knowing:
- Key storage. The Connectors API dev note states that "API keys stored in the database are not encrypted but are masked in the user interface," and that keys are site-wide settings that any installed plugin can access. Storing keys as environment variables or constants in wp-config.php keeps them out of the database.
- Plugin access. Because any plugin can use configured connectors, a poorly built plugin could make AI calls you did not intend. The official AI plugin adds a "Connector Approvals" option that requires an administrator to approve which plugins and themes may use connectors.
The official "AI" plugin
WordPress.org publishes an experimental plugin named AI (version 1.3.0, 50,000+ active installs as of October 2026). Its description calls it both "a practical tool for content creators and a reference implementation for developers." It does not include provider credentials: you install at least one connector plugin and configure it under Settings > Connectors. It requires the block editor; the description states that the Classic Editor is not supported.
Features listed on the plugin page include:
- alt text generation for images,
- title, excerpt, slug and meta description suggestions (the last integrates with various SEO plugins),
- content summarization, resizing (shorten, expand, rephrase) and translation of paragraph and heading blocks,
- content classification (suggested tags and categories),
- comment moderation and suggested replies,
- Editorial Notes that review content block by block for accessibility, readability, grammar and SEO,
- image generation and editing,
- AI request logging, Connector Approvals and optional encryption of provider keys at rest.
The plugin uses an opt-in "experiment" framework, so you enable only the features you want. Because it is labeled experimental, expect changes between versions and test on staging before relying on it.
AI tools and agents outside the dashboard
The MCP Adapter, described on the WordPress Developer Blog as "an official package in the AI Building Blocks for WordPress initiative," exposes abilities to AI agents through the Model Context Protocol. It is not part of core; it is installed as a separate plugin or Composer package. By default, abilities are only exposed if they are explicitly marked public for MCP, and HTTP connections typically authenticate with application passwords. If you connect an external AI agent to your site this way, the agent can do whatever the authenticating user can do, which is a strong argument for a dedicated, limited user account. Our guide to WordPress user roles explains how to set one up.
Plugin options in the wider ecosystem
Many commercial WordPress products now include AI features, often bundled into specific plans. A few examples from vendors' own pricing pages as of October 2026: Astra sells an "Astra Pro + AI" plan, Beaver Builder describes its Plus plan as "now with AI," and Yoast lists a "Yoast SEO AI+" product. These are mentioned for orientation, not as recommendations.
When evaluating any AI plugin, check:
- Whose model and whose key. Does it use the site's Connectors (your provider, your terms) or route content through the vendor's own servers?
- What is sent. The documentation should say which content leaves the site and when.
- Cost. With your own key, you pay the provider per use; with vendor credits, check what happens when they run out.
- Permissions. Which roles can trigger AI features? Contributors generating images on your API key may not be what you intended.
- The usual plugin checks. Active installs, last updated date, tested-up-to version, support activity and security history. Our guide to WordPress plugin security covers these in detail.
Practical uses that tend to work
- First-draft alt text, reviewed by a person who knows what the image is meant to convey.
- Meta description and title suggestions as starting points, edited for accuracy and search intent.
- Summaries and excerpts for long posts and archive pages.
- Tag and category suggestions to keep taxonomy consistent across many authors.
- Editorial checks for readability and grammar before an editor's final review.
- Comment triage, with a human making the final moderation call.
- Translation drafts, checked by a fluent speaker before publishing.
Search visibility depends on usefulness and accuracy, not on whether AI was involved. Our guide to how AI search changes WordPress SEO covers the content side.
Risks to manage
- Accuracy. Models produce plausible but wrong statements. On health, legal, tax or financial pages, every AI-assisted sentence needs expert review.
- Privacy and confidentiality. Do not send customer, patient or unpublished financial data to a provider unless your contracts and policies allow it.
- Key security. Database-stored keys are unencrypted by default; prefer environment variables or constants, restrict admin access and rotate keys if a site is compromised.
- Over-permissioned agents. An AI agent authenticating as an Administrator can do everything an Administrator can. Use least privilege.
- Accessibility. Generic AI alt text ("a person smiling") can be worse than a precise human description.
- Brand and legal. Generated images and text may not match your brand or may raise rights questions; set a written policy for what can be published.
- Cost drift. Bulk actions (regenerating alt text for 5,000 images) can produce surprising API bills.
A sensible rollout plan
- Update to WordPress 7.1.2 and test on staging.
- Write a short AI policy: allowed uses, review requirements, data that must never be sent.
- Choose one provider and store its key as an environment variable or constant.
- Install only the AI features you need and restrict who can use them.
- Pilot with one or two editors, measure time saved and error rates, then expand.
Conclusion
WordPress now has a clean, opt-in foundation for AI: abilities describe what a site can do, the AI Client talks to models and Connectors hold the credentials, with nothing sent anywhere until you configure it. The value and the risk sit in the plugins you add and the review process around them. For more guides, see the WordPress resource hub. If you want help building an AI feature on these APIs, eSEOspace offers WordPress plugin development.
Frequently asked questions
Does WordPress have built-in AI?
It has built-in AI infrastructure (the Abilities API, AI Client and Connectors) but no built-in AI model or provider. Features appear only after you install a provider connector and a plugin that uses it.
Where is the Connectors screen?
Under Settings > Connectors in WordPress 7.0 and later.
Is my API key safe in WordPress?
Keys entered on the Connectors screen are stored in the database without encryption and are masked in the interface. Any installed plugin can read them. Defining keys as environment variables or PHP constants keeps them out of the database; the official AI plugin also offers optional encryption at rest.
Can I stop WordPress from using AI entirely?
Yes. If no provider is configured and no plugin calls the AI Client, nothing is sent. Developers can also block prompts with the wp_ai_client_prevent_prompt filter.
Does AI-generated content hurt SEO?
The method matters less than the result. Pages that are accurate, original and useful can perform well; thin or inaccurate pages tend not to, whoever wrote them.
Put this into action with eSEOspace
We help businesses grow with website design that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!





