NROC GenAI Assessment

The uninfluenced GenAI discovery for enterprises.

NROC Security delivers one easy-to-deploy solution helping enterprises use GenAI securely and productively. Start with the NROC GenAI Assessment to uncover AI usage, data risks, and governance gaps across your organisation.

AICPA SOC 2 examinedGDPR compliant
NIS2 · GDPR · SOC 2 evidence ready
NROC Security Console Assessment mode

GenAI adoption overview

Last 28 days

0 prompts blocked
53
Apps in use
+36.8%
1,500
Active users
+12 pts
139k
Interactions
+11%
Weekly active users21.4% weekly
Classification feed · simulated enforcement
  • ChatGPT · Free/consumerContact information
  • Microsoft Copilot · BusinessLevel 5 · Architect
  • Claude · UnclassifiedSoftware code
  • Gemini · Free/consumerRésumé attachment

Why this matters

Your employees are already using AI. But do you know how?

Before putting the right policies, guardrails, and training in place, you need visibility into how GenAI is actually being used across your organisation. NROC Security research reveals:

GenAI is used at work
31%
of employees regularly use GenAI apps
Shadow AI is real
53
vendors' apps are used by employees
Data is at risk
23%
of file uploads go to free and consumer GenAI apps
Productivity is untapped
5%
of employees use GenAI effectively
Trusted by enterprise & regulated organisations
HornblowerHANDD Business SolutionsCommission for Regulation of UtilitiesRenaissanceTrivore
Discover how your organisation stands

What you gain with Assessment Mode.

Assessment Mode is a two-week review that reveals how GenAI is used across your organisation — and where the biggest risks and opportunities lie.

Visibility

Know where GenAI is being used and how.

Schedule assessment briefing

See which apps are used

Identify which GenAI tools employees use, their use cases, and how frequently they are used.

Uncover Shadow AI

Reveal unapproved tools and usage outside company policies, including where sensitive data may be exposed.

Understand licence usage

Understand licence usage by plan level — free, personal, or business — to allocate licences where they deliver the most value.

What the Assessment delivers

A clear baseline, prioritised for leadership.

See what surveys and policies cannot: a real-world view of GenAI usage, data risk, governance gaps, employee skills, and productivity across your organisation. Switch between the three executive views below.

2Q26 benchmark summary
37
PII & keyword matches
per 100 prompts
23.2%
Files to free/consumer apps
of all attachments
72%
Free/personal share of ChatGPT
of ChatGPT prompts
25.1%
Prompts in expert categories
sensitive topic classes

PII, keywords and topic categories

matches in period
BusinessFree / consumerUnclassified
Contact information28,000
Custom keywords22,000
Software code9,000
Politics11,000
Legal6,500
Healthcare6,500
Financial2,500
U.S. ID numbers500
Banking & credit card numbers300

Attachment file types and content categories

files in period
BusinessFree / consumerUnclassified
Microsoft Office files8,600
Image files5,400
PDF files2,500
Résumés2,400
Contracts700
Invoices600
TXT and CSV files700

Source: NROC Security user base, 2Q26. Contact information, custom keywords and software code dominate the volume, but banking and national ID numbers appear too — and image files reach consumer apps more often than business ones.

See it on your own estate. The same twelve-page executive report, your data, benchmarked against these figures.

Request Executive Sample Report
Role-tailored value

One assessment. Three executive agendas.

The same uninfluenced baseline answers a different question for each seat at the table — exposure, sourcing, and capability.

See the exposure before you write the policy.

Assessment Mode records prompts, responses, attachments and policy hits without enforcing anything — so your baseline reflects real behaviour, not behaviour under observation.

37
PII matches / 100 prompts
23.2%
Files to consumer apps
0
Prompts blocked

Shadow AI, named and counted

53 app families surfaced in a typical estate, including unsanctioned and unclassified models reached outside sanctioned tenancies.

PII and IP leakage quantified

37 PII/keyword matches per 100 prompts and 23.2% of file attachments flowing into free or consumer apps.

No blocking, no broken workflows

Enforcement is simulated: a redaction rule logs 'redacted' while the prompt passes untouched. Nothing is blocked during assessment.

Evidence for NIS2, GDPR and SOC 2

Per-user, per-app and per-category telemetry becomes documented compliance evidence for the assessment period.

Methodology

See your GenAI reality in two weeks with NROC Security.

The Assessment gives you a baseline of AI usage, data risk, governance gaps, employee skills, and productivity across your organisation.

  1. 01Day 1

    Lightweight onboarding

    Deployment through Microsoft Intune with Entra ID SSO app configuration. Scope, access requirements and reporting milestones confirmed in the initial meeting.

    • Device management admin for workstation settings
    • SSO app configuration in Entra ID
    • Zero user disruption, no interference with existing systems
  2. 027–14 days

    Silent baseline observation

    All end-user-visible elements are hidden. Prompts, responses, attachments and metrics are collected continuously with none of the behaviour change monitoring normally induces.

    • Continuous prompt and context capture
    • Policy enforcement simulated, never applied
    • Authentic, uninfluenced usage baseline
  3. 031 day

    AI risk & skill classification

    Deep NLP parsing classifies PII, banking and ID numbers, software code, legal, healthcare and financial content, custom keywords, and the sophistication of every prompt.

    • PII, IP and sensitive-topic detection
    • Attachment type and content categorisation
    • Six-level prompt maturity scoring
  4. 041 hour

    Executive briefing & roadmap

    A board-ready executive report on your own data, benchmarked against the NROC research base, with a guardrail roadmap for the controls the evidence actually justifies.

    • Board-ready executive report
    • Peer benchmark comparison
    • Prioritised guardrail and enablement roadmap
Schedule assessment briefing

About one hour to deploy. Executive report within two weeks. Free until September 30.

Your GenAI reality

Know where your organisation stands.

Your leadership-ready report brings together GenAI usage, approved and unapproved apps, licence types, sensitive data exposure, governance gaps, prompting skills, and optimisation opportunities — benchmarked against NROC research.

Download the 2Q26 benchmark summary

Source: NROC Security user base, 2Q26. © 2026 NROC Security, Inc.

Metric2Q26 peer
Employees active with GenAI31.4%
Active at least weekly21.4%
GenAI app families in use53
Prompts reaching Microsoft Copilot43%
Free/personal share of ChatGPT72%
PII & keyword matches per 100 prompts37
Attachments sent to free/consumer apps23.2%
Prompts at intermediate skill or lower89%
Active users reaching expert level or above48%
NROC AI Effectiveness Index1.4%

NROC Security, built to enable safe GenAI adoption.

Fast deployment, no plugins or agents, out-of-the-box policies, company SSO, and audit-ready compliance.

See NROC Security in action
Executive FAQ

The questions that decide the engagement.

Legal, disclosure, access and outcome — answered plainly, before you take this to your board or works council.