Consulting and recruiting
Insights Association Code of Standards and AI: what it requires
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
The Insights Association Code of Standards applies to AI the same core duties it applies to any research: respondent consent and privacy, honesty with clients about methods, and keeping research data out of non-research uses. The working rule: when AI touches respondent data or produces findings, document consent scope, disclose the method and check the current Code text.
Key takeaways
- The Insights Association Code applies its existing consent, privacy and transparency duties to AI tools; there is no AI exemption.
- Training an internal coding model sits closer to research practice than licensing respondent verbatims to an outside developer.
- Synthetic or AI-written outputs should be labeled in methodology notes and reports, with the validation step described.
- The Code is revised over time, so verify section numbers and effective dates against the current text before relying on any summary.
- Meeting the Code does not prove legal compliance; state privacy laws and client contracts still apply.
What is the Insights Association Code of Standards?#
The Insights Association Code of Standards is the self-regulatory ethics code of the Insights Association, the US trade body for market research and data analytics. Member companies agree to follow it as a condition of membership, and some client contracts and supplier questionnaires reference it directly.
The Code is not a statute, so falling short of it does not by itself create legal liability. It does set the standard that clients, panel partners and the association expect, and a complaint can affect membership. Many of its duties also track what privacy and consumer protection rules already require, so a gap against the Code often points to a legal question worth checking.
The Code is revised from time to time, and the association may publish interpretive guidance or member education alongside it, including on topics such as AI tools and synthetic data. Before relying on any summary, including this one, read the current Code text and its effective date on the association's site.
Which Code duties apply when AI enters a research workflow?#
The Code duties that apply to AI are the ones that already govern respondents, clients and methods. An AI tool gets no exemption: if it reads respondent data, generates data or shapes findings, the existing duties apply to it the same way they apply to a human analyst or a subcontractor.
The table maps each area to the AI question it raises. Section numbers change between editions, so the last column says what to verify rather than citing clauses.
| Code area | What the duty generally covers | AI question it raises | What to verify in the current Code |
|---|---|---|---|
| Respect for respondents and consent | People agree to take part and know who is collecting their data and why | Did consent cover AI analysis, model training or synthetic data built from their answers? | Consent wording, withdrawal rights and any AI-specific language |
| Personal data protection | Collect only what the project needs, secure it and limit access | Does an AI vendor or model see names, emails, IDs or identifying open-ends? | Data minimization, security and third-party handling duties |
| Research versus non-research use | Research data is not used for sales, marketing or other non-research purposes without consent | Is training a commercial model or licensing data still research? | How the Code defines research and non-research activity |
| Transparency with clients | Clients learn the methods, sources and limits behind findings | Were AI coding, AI-written summaries or synthetic sample used, and how were they checked? | Disclosure duties on methods, data sources and subcontracting |
| Honest reporting | Findings are not misrepresented or overstated | Could model-generated answers be presented as human responses? | Rules on misrepresentation and reporting quality |
| Children and vulnerable people | Extra care and parental consent where required | Do training sets or synthetic personas draw on minors' answers? | Age thresholds and special-care provisions |
| Responsibility for subcontractors | The researcher stays accountable for vendors and partners | Does a survey platform or AI provider reserve rights to train on your studies? | Duties to bind and oversee third parties |
Can respondent data go into an AI training set under the Code?#
Respondent data can go into an AI training set only when the use fits what respondents were told and the data is protected the way the Code expects. The Code does not treat model training as automatically research or automatically forbidden; the answer turns on consent scope, identifiability and purpose.
Training an internal model to code open-ended answers for future client projects sits closer to ordinary research practice than licensing verbatims to an outside AI developer. The second use leaves the research context, may count as a non-research purpose, and puts personal details in a third party's hands.
- Read the consent and privacy notice each respondent actually saw, by study or panel period, not the version on your site today.
- Separate agency-owned panel data from client-supplied sample and third-party panel sample, since each carries different terms.
- Remove direct identifiers and screen open-ended text for names, employers, locations and health or financial details.
- Record the purpose in writing: internal research tooling, a client deliverable or an external license.
- Escalate any external license to counsel and, where client data is involved, to the client.
What the Code means for synthetic data and AI-written outputs#
Synthetic data and AI-written outputs fall under the Code's honesty and transparency duties. Clients are entitled to know when answers came from a model rather than people, how the model was conditioned, and how its outputs were checked against human data.
The practical rule is labeling. A topline drafted by AI, a segment boosted with synthetic cases or a concept screened with synthetic personas should be identified as such in the methodology note and the report, with the validation step described. Presenting synthetic answers as sample is the clearest way to fall short of the Code.
Synthetic data also inherits the history of whatever trained it. A persona model built on past studies carries the consent and client-contract limits of those studies, so the honesty question and the consent question have to be answered together.
Illustrative: a tracker agency reviews its AI tools against the Code#
Illustrative: a fictional brand-tracking agency with about 140 employees runs monthly trackers on a commercial survey platform, codes open-ends with an AI tool and drafts toplines with a writing assistant. An AI developer then asks whether the agency would license its archive of verbatim responses.
The compliance lead maps each tool to the Code. Open-end coding stays after the vendor confirms in writing that it does not train on customer content. AI-drafted toplines stay, with a line in every methodology note saying so and naming the analyst who checked them. The verbatim license is declined because the panel notice never mentioned outside AI training and much of the sample came from client customer lists.
The agency looks instead at its own operational records: proposals, questionnaire review comments, quality-control logs and project post-mortems, with client names removed. Those records describe how researchers work rather than what respondents said, so the consent problem does not arise in the same way.
Where the Code ends and the law begins#
The Code sits on top of the law, not in place of it. Meeting the Code does not prove legal compliance, and a legally permitted use can still fall short of the Code if respondents were never told about it.
Two legal points come up often in AI reviews. California's privacy law sets a three-part test for deidentified data: reasonable measures so it cannot be tied back to a consumer or household, a public promise never to reidentify it, and contract terms that carry the same promise to every recipient. A February 2024 FTC staff post also cautioned that companies which rewrite terms or privacy policies after the fact to allow uses such as AI training may be engaging in unfair or deceptive practices.
Other state privacy laws, sector rules and client contracts may also apply. They are assessed project by project, and deal by deal for any license, with counsel.
How SourceX applies the Code in a licensing review#
SourceX treats the Code as one input to the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. For a research agency, that means checking respondent consent, client contracts and Code duties before any record is in scope, and the first fit check asks for metadata about systems and studies, not files.
Where a package proceeds, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. Agencies usually find their internal process records, such as proposals, questionnaire reviews and project post-mortems, are a better first candidate than respondent-level data.
Frequently asked questions
Does the Code apply to agencies that are not Insights Association members?
Not directly. The Code binds members as a condition of membership. Non-members still meet it in practice when clients write it into contracts, when panel partners require it, or when a buyer of research uses it as the benchmark for acceptable practice. Many non-members follow it voluntarily for those reasons.
Do we have to tell respondents that AI will analyze their answers?
Check the current Code and your privacy notice together. Using AI as an analysis tool inside a project is closer to existing practice than using answers to train a model or build a product. Where a use goes beyond what respondents were told, updated notice for future studies, and consent where needed, is the safer path.
How does the Insights Association Code relate to the ESOMAR code?
ESOMAR publishes an international code that covers similar ground: respect for data subjects, consent, transparency and the separation of research from non-research activity. Agencies that field studies outside the US often follow both, and where the two differ, many apply the stricter rule across a multinational study.
Who inside an agency should own Code compliance for AI?
Usually the person who already owns privacy and quality, often a compliance lead or chief research officer, working with IT on vendor terms. The owner keeps an inventory of AI tools, the data each one touches and what each vendor may do with it, and reviews it whenever the Code or a vendor's terms change.
Can a client waive Code obligations in a contract?
A client can agree to methods and disclosures, but it cannot waive duties owed to respondents, such as honoring consent and protecting personal data. Those duties run to the people who answered the survey. Contract terms that conflict with the Code are a signal to take the question to counsel before fieldwork starts.
Sources
- Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, deidentified information requires reasonable measures against reidentification, a public commitment not to reidentify, and contractual obligations on recipients. Source
- FTC staff warned on February 13, 2024 that adopting more permissive data practices, such as using consumer data for AI training, through a surreptitious, retroactive change to terms or a privacy policy may be unfair or deceptive. Source
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo AI labs buy code?
- InsightHow do I de-identify contracts and legal documents for AI training?
- InsightHow do I de-identify internal documentation for AI training?
- InsightHow do I de-identify knowledge base articles for AI training?
- IndustryBPO & contact centers data
See if your company qualifies
A short company assessment. No data uploads are needed.