Skip to content

Consulting and recruiting

AI policy template for market research agencies

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A market research AI policy should say which AI tools staff may use, what client and respondent data may go into them, when clients are told, how AI-generated outputs are labeled and reviewed, and how vendor terms are checked. Map each section to your research code and client contracts, then test that daily practice matches the document.

Key takeaways

  • Start with an approved-tools register; most other rules depend on which tools are allowed and on what terms.
  • Keep separate rules for client materials, respondent personal data and the agency's own records.
  • Label synthetic data and AI-coded outputs wherever they appear in a deliverable.
  • Review each vendor's terms on training, retention and subprocessors before approval and at renewal.
  • Schedule spot checks of delivered projects, because a policy nobody follows gives false comfort.

What should a market research AI policy cover?#

A market research AI policy covers four things: which tools are allowed, what data may go into them, what clients and respondents are told, and how people check AI output before it reaches a client. Every section of the template supports one of those four.

Write it for the people who will use it: project managers, analysts, moderators, coders and freelancers. Short rules with examples from your own studies work better than general principles, and a one-page summary attached to the project kickoff checklist carries the rules into real work.

Sort data into three classes before writing any rule. Client materials, such as briefs, stimuli, brand plans and results, are governed by the master agreement. Respondent personal data, such as screener answers, contact details, recordings and identifiable verbatims, is governed by consent and privacy law. The agency's own records, such as questionnaire libraries, codeframes and proposals, are governed by internal policy. A tool can be approved for one class and barred for another.

The template, section by section#

Use these sections as the skeleton of the policy. The third column names the obligation each section serves, so you can check coverage against the research code your agency follows and against your client contracts.

The template, section by section
SectionWhat it saysObligation it serves
Scope and definitionsWhich staff, freelancers and tools are covered, and what counts as AIClarity on who must comply
Approved tools registerNamed tools, approved uses and the account type for eachVendor terms and data security
Client data rulesWhich client materials may enter which toolsClient confidentiality and MSA terms
Respondent data rulesWhen personal data may be processed by AI, and how it is minimizedRespondent privacy and consent
Recording and transcriptionRules for AI notetakers and transcription in sessionsParticipant consent and recording laws
Disclosure to clientsWhen and how AI use appears in proposals and reportsTransparency with clients
Labeling outputsHow synthetic data, AI-coded verbatims and AI drafts are markedHonest reporting of methods
Human reviewWho checks AI output and what they checkQuality and accountability
Fieldwork qualityUse of AI to detect bots and fraud, and how removals are reportedData integrity
RetentionHow long prompts, uploads and outputs are keptData minimization
IncidentsSteps when restricted data reaches an unapproved toolBreach and contract notice duties
Training and reviewOnboarding, attestations and the policy review cycleKeeping practice aligned with policy

Vendor terms: the review behind every approved tool#

Vendor terms decide whether a tool can go on the register, so the policy should require a terms review before approval and again at renewal. The review answers a short set of questions, recorded against the specific plan the agency holds.

Answers differ by product and plan. Zoom's terms state that it does not use audio, video, chat or other communications-like customer content to train Zoom or third-party AI models. For Microsoft 365 Copilot, Microsoft's enterprise data protection documentation says prompts, responses and data reached through Microsoft Graph are not used to train foundation models. Notion says its model providers keep no customer data by default for Enterprise workspaces but may keep it for a limited period on other plans. A consumer account of the same product may sit under different terms entirely.

  • Does the vendor use customer content to train its own or third-party models, and is that default on or off?
  • How long do the vendor and its model providers keep prompts, uploads and outputs?
  • Which subprocessors handle the data, and in which countries?
  • Who owns outputs, and are they treated as customer content or confidential information?
  • Does the business plan differ from the consumer plan on any of these points?

Disclosure and labeling: what clients and respondents should see#

Disclosure rules tell project teams when to mention AI to clients; labeling rules tell them how to mark AI-influenced outputs. A workable standard is to name the stages where AI was used in the proposal and the methods section, confirm human review, and label anything a reader could mistake for direct human data.

Synthetic respondents need the clearest labels. A chart that mixes synthetic and human answers without marking them misstates the evidence behind a client's decision. AI-coded verbatims should note that a person validated the coding, and AI-drafted session summaries should be checked against the transcript before anyone quotes them.

Respondents need notice too. If an agency starts processing panel answers with AI in ways its privacy notice did not describe, the notice should change before the practice does. FTC staff have warned that quietly changing terms of service or privacy policies to permit more permissive uses, such as AI training, could be unfair or deceptive.

Closing the gap between policy and practice#

The usual failure in an AI policy is not a missing section but a document that describes something the agency does not actually do. These steps keep the written rules and daily work aligned.

  • Build the tools register from expense reports, single sign-on logs and a short staff survey, not from memory.
  • Add an AI line to the project kickoff checklist: which tools, which data and what the client contract allows.
  • Spot-check a sample of delivered projects against the policy at each review.
  • Collect a short attestation from staff and freelancers at onboarding and after each policy update.
  • Log every exception with a reason and an approver, and review the log before revising the policy.

Illustrative: a mixed-method agency writes its first policy#

Illustrative: a fictional mixed-method agency runs online surveys, in-person groups and remote interviews. Its moderators had started using an AI notetaker in remote interviews, and analysts were pasting verbatims into a consumer chatbot to draft codeframes.

The compliance lead builds the register first. The notetaker is approved on its business plan, with recording and transcription consent added to the screener. The consumer chatbot is replaced by an enterprise account whose terms exclude training on customer content. One client's master agreement prohibits any third-party AI on its studies, so that client goes into the kickoff checklist as a named exception.

The first spot check finds a few reports where AI-coded verbatims were not labeled. The fix is a standard line in the report template rather than a new rule.

How the policy connects to your archive and to SourceX#

An AI policy also documents how records were handled, which matters if the agency later considers licensing its own archive. Studies processed only in approved tools, with clear client permissions and labeled synthetic data, are far easier to trace than studies that passed through unknown accounts.

SourceX reviews those facts in the Rights and Preparation steps of the SourceX five-step transaction. The permitted use and privacy record in a SourceX Evidence Packet draw on the same answers the policy already requires: which data, which tools and which consents.

Frequently asked questions

Do freelancers and subcontracted moderators need to follow the policy?

Yes, if they touch client or respondent data. Put the key rules in their contracts, give them access to approved tools so they do not fall back on personal accounts, and collect the same attestation you ask of staff. Freelancers are a common route for data to reach unapproved tools.

Can staff use free consumer AI tools for anything?

A common rule allows consumer tools only for work with no client or respondent data, such as drafting internal emails or brainstorming from public information. Write that boundary down with concrete examples, because otherwise each person judges it case by case.

Does the policy need client approval?

No, but clients may ask for it in security questionnaires and RFPs, and some master agreements require the agency to follow client-specific AI rules. Keep a client-facing summary ready and record client restrictions as named exceptions in the register.

How often should the policy be reviewed?

Review it on a fixed cycle and whenever a tool, a major client contract or a relevant law changes. Vendor terms change often, so the tools register needs more frequent checks than the policy text itself. Assign one owner to watch vendor notices and flag changes to training or retention terms.

Should the policy cover AI used to detect survey fraud?

Yes. Fraud detection decides which respondents are removed, so document the tools, the rules they apply and how removals are reported to clients. Keep the removal decisions with the study file; that record helps if a client questions sample quality later and shows the method behind the final base.

Sources

  • Zoom's Terms of Service (Section 10.2) state that Zoom does not use audio, video, chat, screen sharing, attachments or other communications-like Customer Content to train Zoom or third-party AI models. Source
  • Microsoft's enterprise data protection documentation for Microsoft 365 Copilot states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. Source
  • Notion states that LLM providers use zero data retention by default for Enterprise plan workspaces, while for non-Enterprise workspaces they retain Customer Data for a limited period before deletion. Source
  • FTC staff warned on February 13, 2024 that adopting more permissive data practices, such as AI training, through a surreptitious, retroactive change to terms or privacy policies may be unfair or deceptive. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify