Research Ethics, Privacy and AI Governance
Everything in the preceding chapters runs ahead of the regulatory and ethical framework that is supposed to govern it. Synthetic respondents, AI interviewers, behavioural surveillance, automated analysis — none of these existed when the current codes of conduct were written. This chapter is about the rules being rewritten, the gaps that remain, and the oldest question in research ethics wearing new clothes: what do the people who provide the data actually deserve?
M6 / 9 published articlesThe rules are catching up. The question is whether they will catch enough.
Market research has always governed itself. Unlike medicine or finance, it has no statutory regulator in most jurisdictions. What it has is a shared code of conduct — the ICC/ESOMAR code — a set of professional norms, and an implicit bargain with participants: we ask, you answer, we protect your data, and the exchange is roughly fair. That self-governance worked tolerably well when the main risk was a poorly worded question or a mishandled dataset.
The risk surface is now larger. An AI interviewer collects data a human interviewer never could — tone, hesitation, word choice analysed at scale — and the consent form that covered a questionnaire does not cover that. A digital twin carries a person's profile indefinitely, raising questions about ownership that existing privacy law does not cleanly answer. A synthetic respondent generates data that looks real and is not, and the disclosure standards that would let a client tell the difference do not yet exist as enforceable rules. A foundation model trained on behavioural data can be used for research or for targeting, and the line between the two, always contested, is now almost invisible.
This chapter is where the corpus refuses to separate the question of what works from the question of what is right. The tools described in the previous chapters are powerful. Whether they are used well is a governance question, and the governance is still being written.
Why this matters to you
If you commission or conduct research, the regulatory environment around you is changing. The EU AI Act classifies some research applications as high-risk. The rewritten ICC/ESOMAR code now covers AI and synthetic data explicitly, though enforcement lags behind the text. Clients are beginning to ask about synthetic disclosure and consent protocols, and the vendors who cannot answer clearly are going to lose business. At a more fundamental level, the people who answer your surveys, join your panels, and leave the behavioural traces you analyse are increasingly aware that the exchange is not fair — that their data is worth more than a gift card, and that their consent was to something narrower than what is being done with it. This chapter gives you the framework for navigating that: what the new rules require, where they fall short, and what a responsible practice looks like before the rules catch up.
What you'll find inside
The pieces here run from the formal rules to the unresolved questions. You will start with the 2025 code itself — the first rewrite to cover AI, synthetic respondents, and automated decision-making — and why a code that names those duties cannot yet enforce them. You will see the disclosure problem: what "label the synthetic" means in practice and why most of the industry is not doing it. You will confront consent in the machine age, what participants actually agreed to and what is being done beyond that agreement, and the ownership question raised by digital twins — who controls a computational likeness, and what rights travel with it. You will meet privacy engineering as a discipline rather than a compliance checkbox, and see regulation reaching fieldwork directly through the AI Act. The chapter revisits dual use — the same technique serving both understanding and manipulation — and closes with two pieces that point at the profession itself: the panel economy and what the people who answer are owed, and proof of rigour, the emerging practice of showing your holdout, your pre-registration and your audit trail as a condition of being believed.
The honest note
The characteristic caveat for this chapter is that governance is lagging, and self-governance has a conflict of interest. The industry writing the rules is also the industry whose revenue depends on the tools the rules constrain. That is not a reason to dismiss the effort — the ICC/ESOMAR code is a genuine attempt, and the people drafting it take the work seriously — but it is a reason to expect the rules to arrive late and with gaps. The harder truth is that compliance is not ethics. A practice can be technically legal, formally code-compliant, and still wrong, because it exploits a consent that was given for something narrower, or because it extracts value from participants who see none of it returned. The closing question of this chapter, and of the whole corpus, is whether the profession will hold itself to the standard it would want applied to its own data — not just the standard it can get away with.
The nine pieces in this chapter
- "The research code caught up with AI. Enforcement did not." — the 2025 code
- "Label the synthetic" — disclosure
- "What did they agree to?" — consent in the machine age
- "Your likeness, licensed" — who owns the twin?
- "Research inside the vault" — privacy engineering
- "The AI Act meets the discussion guide" — regulation reaches fieldwork
- "Effective and ethical, again" — dual-use insight
- "Who pays the people who answer?" — the panel economy
- "Show your holdout" — proof of rigour
Read the articles
- M6-01
The ICC/ESOMAR Research Code: The Research Code Caught Up With AI. Enforcement Did Not.
- M6-02
Disclosing Synthetic Research Reduces Trust
- M6-03
Research Consent and AI Training: You Can Withdraw Consent, But The Model Won't Forget.
- M6-04
Digital Twin Ownership: Build a Double of a Real Panellist. Now Who Owns It?
- M6-05
Privacy-Preserving Research: How to Measure What You Can No Longer See
- M6-06
The EU AI Act and Research: The AI Act Meets the Discussion Guide
- M6-07
AI Persuasion, Measured and Deployed: The Model That Measures Persuasion Can Also Be Used to Persuade
- M6-08
Survey Incentives and Data Fraud: When Faking a Survey Costs Less Than Answering It
- M6-09
Auditing Research Accuracy Claims: Proof Is an Accuracy Figure on a Holdout the Seller Didn't Choose
Let’s talk
Invisible forces shape your world — until you hire Latenta®
Contact