See which apps are used
Identify which GenAI tools employees use, their use cases, and how frequently they are used.
NROC Security delivers one easy-to-deploy solution helping enterprises use GenAI securely and productively. Start with the NROC GenAI Assessment to uncover AI usage, data risks, and governance gaps across your organisation.


GenAI adoption overview
Last 28 days
Why this matters
Before putting the right policies, guardrails, and training in place, you need visibility into how GenAI is actually being used across your organisation. NROC Security research reveals:
Assessment Mode is a two-week review that reveals how GenAI is used across your organisation — and where the biggest risks and opportunities lie.
Identify which GenAI tools employees use, their use cases, and how frequently they are used.
Reveal unapproved tools and usage outside company policies, including where sensitive data may be exposed.
Understand licence usage by plan level — free, personal, or business — to allocate licences where they deliver the most value.
See what surveys and policies cannot: a real-world view of GenAI usage, data risk, governance gaps, employee skills, and productivity across your organisation. Switch between the three executive views below.
Source: NROC Security user base, 2Q26. Contact information, custom keywords and software code dominate the volume, but banking and national ID numbers appear too — and image files reach consumer apps more often than business ones.
See it on your own estate. The same twelve-page executive report, your data, benchmarked against these figures.
Request Executive Sample ReportThe same uninfluenced baseline answers a different question for each seat at the table — exposure, sourcing, and capability.
Assessment Mode records prompts, responses, attachments and policy hits without enforcing anything — so your baseline reflects real behaviour, not behaviour under observation.
Shadow AI, named and counted
53 app families surfaced in a typical estate, including unsanctioned and unclassified models reached outside sanctioned tenancies.
PII and IP leakage quantified
37 PII/keyword matches per 100 prompts and 23.2% of file attachments flowing into free or consumer apps.
No blocking, no broken workflows
Enforcement is simulated: a redaction rule logs 'redacted' while the prompt passes untouched. Nothing is blocked during assessment.
Evidence for NIS2, GDPR and SOC 2
Per-user, per-app and per-category telemetry becomes documented compliance evidence for the assessment period.
The Assessment gives you a baseline of AI usage, data risk, governance gaps, employee skills, and productivity across your organisation.
Deployment through Microsoft Intune with Entra ID SSO app configuration. Scope, access requirements and reporting milestones confirmed in the initial meeting.
All end-user-visible elements are hidden. Prompts, responses, attachments and metrics are collected continuously with none of the behaviour change monitoring normally induces.
Deep NLP parsing classifies PII, banking and ID numbers, software code, legal, healthcare and financial content, custom keywords, and the sophistication of every prompt.
A board-ready executive report on your own data, benchmarked against the NROC research base, with a guardrail roadmap for the controls the evidence actually justifies.
About one hour to deploy. Executive report within two weeks. Free until September 30.
Your leadership-ready report brings together GenAI usage, approved and unapproved apps, licence types, sensitive data exposure, governance gaps, prompting skills, and optimisation opportunities — benchmarked against NROC research.
Download the 2Q26 benchmark summarySource: NROC Security user base, 2Q26. © 2026 NROC Security, Inc.
Explore NROC Security research on adoption, prompting maturity, and how to quantify meaningful productivity gains from GenAI.
NROC Security, built to enable safe GenAI adoption.
Fast deployment, no plugins or agents, out-of-the-box policies, company SSO, and audit-ready compliance.
Legal, disclosure, access and outcome — answered plainly, before you take this to your board or works council.