On September 2, 2026, at Webflow Conf 2026 in Boston, Webflow announced Source, a new agentic platform, according to a GlobeNewswire press release. The headline detail: agents get direct access to the underlying codebase, not a walled-off visual abstraction layer, so they can do what Webflow calls production-level work, while marketers build visually on top of that same code at the same time, inside role-specific, governed workspaces. Agents also autonomously watch site and campaign performance and surface recommendations grounded in historical data. It's built to plug into existing codebases and martech stacks rather than replace them. CEO Linda Tong put it plainly: "The people with the ideas, taste and ambition to build something great are getting entirely new superpowers." Source is not shipping broadly yet -- it's a limited research preview with an application process, not general availability.
Webflow's entire original pitch was that you didn't need to touch code -- visual building was the point, and the abstraction layer was the product. Source inverts that for agents specifically: instead of keeping AI behind the same visual guardrails a human designer works within, Webflow is letting agents reach into the code directly. That's a meaningfully different bet than most "AI features bolted onto an existing tool" announcements we've covered this year, and it deserves a straight answer instead of a dismissal. We've written before about how Webflow compares to ViibeStack on the no-code spectrum broadly; Source changes part of that comparison, and it's worth being honest about why.
Here's the case for Webflow's approach, argued fairly: Source exists to extend and optimize websites and codebases that already exist, are already complex, and can't be thrown out and rebuilt. A large marketing site with years of custom code, integrations, and brand-specific logic is a legacy system in the real sense -- it has to keep working while you improve it. If you're retrofitting agents onto something like that, giving them access to the actual code they need to modify is a defensible, pragmatic call, not a reckless one. Matt Varughese's line about running "agents with real guardrails so work gets done while you sleep" is a legitimate vision for that specific problem: a team that already has a codebase and needs agents to operate inside it safely. That's a real bet, made by a well-resourced company, for a real use case. We're not going to pretend otherwise.
But retrofitting agents onto an existing, complex system is a different problem than building a new, purpose-built tool for a specific workflow from scratch. When there's no legacy codebase to preserve compatibility with -- say, an internal approvals tool, a customer intake form, or a lightweight CRM built to replace a spreadsheet -- choosing not to expose generated code isn't a workaround for a limitation. It's a deliberately clean starting point that never needed code-level governance in the first place, because there's no code-level surface for anything to go wrong on. This is the logic behind how ViibeStack's AI App Builder and platform work: when you're generating something new for a narrow purpose, keeping it in a governed, visual, permissioned layer removes an entire category of risk rather than managing it after the fact. That's not a limitation compared to Source -- it's a different problem being solved with a different starting point, and conflating the two is where a lot of "no-code vs. AI-native code" debates go wrong.
"Real guardrails" is doing a lot of work in Webflow's pitch, and it's fair to point out that this exact promise has a documented gap industry-wide. Research from Cequence Security and EMA, which we covered in detail here, found that 94% of organizations were confident their AI agents were properly scoped -- while only 33% were actually enforcing least-privilege access in practice. That gap between confidence and enforcement is the single biggest reason to treat "agents with guardrails, running while you sleep" as an unproven claim right now, for any vendor making it, not a settled fact. This isn't a specific knock on Source, which just launched in limited preview and hasn't been tested at scale by outside teams yet. It's a reason to withhold judgment until there's real evidence, and a reason we've built our own role-based permissions and security posture around enforcement you can actually inspect, not just describe.
Webflow isn't wrong to make this bet, and Source isn't evidence that visual, no-code building is obsolete. It's evidence that the right amount of code exposure depends entirely on what you're building on top of. If you're extending a decade-old marketing site with a sprawling codebase, agents with governed code access might genuinely be the right tool. If you're building a new internal tool, a customer-facing workflow, or a small business app with no legacy system to protect, a clean visual layer isn't a compromise -- it's the better architecture for that job. That's the distinction worth holding onto as more vendors, including Webflow, start making agentic promises this year.
Sources