Governing AI That Acts with Tas Jalali
Governing AI That Acts
By CISO, AC Transit
Governing AI That Acts: The Execution-Layer Challenge
For most of my 25 years in security, technology waited for a human to decide. That era is ending. The defining challenge I face today as CISO of AC Transit, California’s largest bus-only public transit system, is governing AI that no longer just recommends, but executes.
The risk does not always arrive through a new procurement. Increasingly, AI capabilities appear inside SaaS products the organization already trusts, switched on by the vendor without a separate review or approval. The perimeter question is no longer only “what are we buying” but “what has our existing software quietly become.”
Our answer was to treat AI governance as an engineering discipline, not a policy binder. In October 2024, our Board adopted the first enterprise AI policy in the agency’s history, backed by a 10-step workflow that carries every use case from identification through production, and an AI-specific vendor assessment now built into renewals, renegotiations, and new reviews. Three questions anchor it: What types of our data can your AI features or agents access? Can they be enabled or disabled by our organization? Do you use our data to train, fine-tune, or improve your models? Asked consistently, these give Security, Legal, Privacy, and Procurement shared visibility and real negotiating leverage. That framework has since shaped our responses to federal DOT rulemaking, and through chairing APTA’s national AI Subcommittee, I see agencies nationwide facing the same question: how to say yes to AI without surrendering accountability.
The principle underneath it all, one I explore in my book Applied AI Governance, is to govern AI at the execution layer. Treat every agent like a privileged employee: verified identity, least privilege, full audit logging, and a kill switch. In critical infrastructure, control is what makes innovation survivable.
About Tas Jalali, CISO, AC Transit
Tas Jalali is a CISO, author, speaker, and advisory board member to several AI startup companies, with a focus on AI governance and cybersecurity. He serves as Chief Information Security Officer at AC Transit, chairs the AI Subcommittee of the American Public Transportation Association, and advises AI startups on governance and security. He is the author of Applied AI Governance (Amazon, 2026) and holds a graduate degree from Harvard University.
SHARE THIS ARTICLE