Content leaders are shopping for new technology again, and it doesn't matter whether their DAM is one year old or ten. That was the clearest signal from our week in New York, where we spent two days at Henry Stewart's DAM NY and then co-hosted Where Content Meets AI, an evening roundtable with Monks, LucidLink and AWS.
Here's what we kept hearing, on the conference floor and over dinner.
A busier vendor floor, and sharper buyers
DAM NY had more sponsors this year than I remember in prior years (estimating about 250 in total), mostly software vendors and consultancies, and fewer end users (about 300) in the room. That many vendors in one hall tells you money is flowing into content technology right now. For some first-time attendees, it was overwhelming at times.
DAM NY 2026, by our estimate
The smaller practitioner crowd made for better conversations. Most of the people we spoke to already had a project underway, or were planning one, and came with a shortlist and hard questions, particularly around content digitization strategies and rights management.
Content and AI is the hot topic, but the DAM isn't always invited
Almost every conversation ended up on AI. What surprised us was how many AI content projects are running around the DAM rather than through it. Teams generate assets in gen-AI tools and agency platforms, and a lot of that output never makes it into a governed system.
The phrase we heard most
Content is everywhere, not just in the DAM.
It sits in cloud storage, creative tools, gen-AI platforms, commerce systems and social channels. Nobody we spoke to saw that as a discipline problem to fix. It's simply how content works now. Two years ago, DAM teams pushed back on that. Now they're planning around it.
DAM as a category was built on the idea that content lives in one place. If that's no longer true, the DAM's job changes. It becomes the record of what each asset is, who can use it and where, regardless of where the file is stored.
This came up a lot at the dinner with Monks, LucidLink and AWS, where the topic was how to scale content operations. We all agreed that the more content spreads out, the more you need one record you can trust. And one thing stood out over dinner: for all the talk about tech and models, people still really value time together in the same room.
New DAM or old DAM, everyone is evaluating again
Teams that bought a DAM last year were often just as unhappy as teams running the same one for a decade.
When a brand-new system and a ten-year-old one disappoint in the same way, the problem isn't the age of the system. It's the architecture.
The trigger is the Model Context Protocol (MCP), the open standard that lets AI agents connect directly to business systems and act on their data. Buyers still care whether their team can find an asset in the portal, but now they also ask whether an agent can get to that content and use it safely.
MCP itself is moving quickly. The July 2026 revision made the protocol stateless and tightened authorization, so a lot of MCP integrations built in the last two years will need rework. If a vendor tells you they support MCP, ask which version and how agents authenticate.
Most DAMs were designed for people clicking through an interface. Buyers now want a platform that agents and other systems can work with directly, and that's what they're judging vendors on.
Who gave the agent the keys?
Once agents can connect, the question is what they're allowed to do. Many content systems still rely on shared integration accounts, broad API scopes and rights rules that only exist in the user interface. Agents never see the interface; they work through the API. So a system built for people can end up giving an agent full access with nothing to hold it back.
That was the topic of Who gave the agent the keys?, the session Neil Grant, VP of Content Intelligence at Tenovos, gave at the conference. It was a gem of a talk. In the hall afterwards, we overheard someone say, “I’m sending that deck to my team this afternoon.” His framework, the Agent Ladder, puts every agent on exactly one rung. Moving an agent up a rung should be as deliberate as giving someone admin rights.
The Agent Ladder · four tiers of agent access
Every rung up the Agent Ladder is a deliberate grant of power
- Tier 3Publish
Distributes to CDNs, storefronts and partner feeds. A named human approves every action.
- Tier 2Derive
Creates crops and renditions. Derivatives inherit rights; agents can't edit rights fields.
- Tier 1Propose
Writes enriched metadata to a review queue. Humans accept or reject; graduate field by field.
- Tier 0Read
Finds, summarizes and suggests tags in named collections. Reading everything is an export path.
Three points from the session that people brought up with us afterwards:
Scope matters more than mode.
A read-only agent that can read everything is an export path.
Pipelines can copy pixels and lose constraints.
A crop or rendition has to inherit the rights and territory of its master.
Reversibility, not accuracy, decides whether a human stays in the loop.
Publishing can't be undone, so a named person approves it.
Neil closed with four questions every team should ask its DAM vendor before connecting an agent:
Identity
Can each agent have its own credentials, tied to a named person?
Enforcement
Are rights enforced at the API layer, or only in the interface?
Audit and undo
Can you see everything an agent did and reverse it in bulk?
Kill switch
Is there a kill switch you can pull without filing a support ticket?
The full handout is available here: The Agent Ladder.
The takeaway
What it means for content leaders
- 1
First, the big picture. Anyone working with images, video or any other content has a real chance to grow, cut costs and make more money from it by using AI across the supply chain. At the same time, AI has made it harder for vendors to stand apart, so buyers have a lot of options and decisions take longer. Bad for vendors, better for brands, and really good for consultancies.
- 2
Second, if you're evaluating a DAM this year, start with two questions. Can agents reach your content through a current version of a standard like MCP? And are your rights and approvals enforced where agents actually work, at the API, and not only in the interface? This should get the conversation off on the right foot.
Finally, a big thanks to Monks, LucidLink and AWS for co-hosting the dinner, to Henry Stewart for another fine DAM NY, and to everyone who talked with us during the week.
Frequently Asked Questions
What were the main themes at Henry Stewart DAM NY 2026?
Four themes came up repeatedly: a busier vendor floor with fewer but more focused buyers, AI content projects running around the DAM instead of through it, teams with both new and old DAMs evaluating again, and how much access AI agents should get to content systems.
Why are teams with a new DAM evaluating again?
Teams that bought a DAM in the last year were often as unhappy as teams running the same system for a decade. When new and old systems disappoint in the same way, the problem is the architecture, not the age. Most DAMs were built for people clicking through an interface, while buyers now need platforms that AI agents and other systems can work with directly.
What is the Model Context Protocol (MCP) and why does it matter for DAM?
The Model Context Protocol (MCP) is the open standard that lets AI agents connect directly to business systems, read their data and take action. For a DAM, MCP decides whether an agent can reach your content, understand it and act on it safely.
What changed in the 2026-07-28 MCP specification?
The 2026-07-28 revision of the MCP specification made the protocol stateless and tightened authorization. Many MCP integrations built before it will need rework, so buyers should ask vendors which MCP version they support and how agents are authenticated.
Why does content living outside the DAM change the DAM's role?
Content now sits in cloud storage, creative tools, gen-AI platforms, commerce systems and social channels. When files live everywhere, the DAM's job shifts from storing every file to being the governed record of what each asset is, who can use it and where.
What is the Agent Ladder?
The Agent Ladder is a framework from Neil Grant, VP of Content Intelligence at Tenovos. It places every AI agent on exactly one of four tiers of access: Read, Propose, Derive and Publish. Moving an agent up a tier should be as deliberate as granting admin rights, and any action that can't be undone, like publishing, needs approval from a named person.
What should you ask a DAM vendor before connecting an AI agent?
Can each agent have its own credentials, tied to a named person? Are rights enforced at the API layer, or only in the interface? Can you see everything an agent did and reverse it in bulk? Is there a kill switch you can pull without filing a support ticket?