The ICC/ESOMAR Research Code: The Research Code Caught Up With AI. Enforcement Did Not.

Article M6-01

In 2025, the research industry rewrote its core code to cover AI, synthetic data, and synthetic respondents for the first time. The code can name those duties. It binds only members who agreed to it. The fastest-moving problems come from firms that never signed.

In brief

The research industry governs itself with a shared code of conduct, not a law. In 2025, the International Chamber of Commerce and ESOMAR published the fifth edition, the first to name artificial intelligence, synthetic data, and synthetic respondents and set duties around them. The previous 2016 edition assumed human interviewers and human answers. A voluntary code binds only the members who agreed to it, usually the suppliers already trying to behave. It cannot reach the non-members driving the AI-era problems it names. The 2025 Code raised the standard for the responsible and left the irresponsible where they were.

What the theory says

The theory

Since 1948, the research industry has used a shared rulebook. Its modern form is the International Code on Market, Opinion and Social Research and Data Analytics, published jointly by the International Chamber of Commerce and ESOMAR. The two bodies have run it together since 1977. The fourth edition appeared in 2016 (ICC/ESOMAR, 2016). In June 2025, ICC and ESOMAR approved a fifth edition. They released it publicly on 29 September 2025 (ICC/ESOMAR, 2025). As of now, the fifth edition remains current.

The 2025 edition is the first to name artificial intelligence, synthetic data and synthetic respondents. It introduces a duty of care: a general obligation to avoid foreseeable harm to the people affected by the work. It strengthens disclosure and transparency requirements and adds guidance on publishing research produced with AI. Earlier editions governed a world of human interviewers and human respondents. The 2025 edition tries to govern a world in which suppliers can generate answers without contacting a person. A code shows what good behaviour is claimed to look like; it does not prove that the claim holds in practice.

The ICC/ESOMAR Code is soft law: a voluntary, principles-based set of rules that members agree to follow rather than legislation that a government enforces. Its authority comes from membership and reputation, not from the courts. Soft law can change faster than a statute, so the research bodies could respond to AI while governments were still drafting hard law. Barda, Shaked and Murtazashvili (2025) describe such arrangements as coordinated self-regulation, where an industry sets shared rules through a central body rather than leaving each firm to its own devices.

Having a code does not reliably change behaviour. This is a pre-2022 prior, not a new finding. Kaptein and Schwartz (2008) reviewed 79 empirical studies of business codes. They found mixed results: about 35% of the studies concluded that codes were effective, and roughly a third found no significant relationship between having a code and how people behaved. That work concerns general business ethics, not market research, and it predates the AI era. It is therefore a prior rather than direct evidence about this Code. The direction still matters. A code on paper is not the same as conduct in the field. The duties in the 2025 rewrite are new and serious. Writing them down is the easy part.

Controversies

As of now, the live question remains whether a voluntary code can reach the AI-era problems it now names. The most direct evidence comes from AI governance generally. Marchant and Gutierrez (2023) reviewed more than 600 AI soft-law programmes. They found a recurring weakness: voluntary instruments are good at naming duties and poor at implementing or enforcing them. They argue that soft law is worth keeping because it can keep pace with technology that moves faster than legislatures. They also set out mechanisms meant to give it more credibility. The result is positive on speed and clear about the enforcement hole. The 2025 Code sits inside that tension.

Soft law also stands in relation to hard law. Xiao and Sun (2025) argue that the relationship is hybrid: soft law guides early practice while hard law supplies enforceable minimums. Kim and Jon (2026) complicate that split by showing that even laws people call hard often carry soft, under-enforced provisions. For research, the practical version is the contrast between the Code and the EU AI Act, covered in [M6-06]. One is voluntary and fast; the other is binding and slow. Alanoca et al. (2025) map the wider picture and show that AI regulation worldwide is a patchwork of overlapping instruments rather than a single settled regime.

The nearest evidence comes from other industries that run voluntary codes, and it is not encouraging. Casey (2023) examined responsible-gambling codes and found that trade associations tend to reproduce them in ways that protect the industry as much as the public. Lexchin (2023) examined complaints about pharmaceutical industry-run promotion codes and documented how self-run enforcement can fall short. Both are cross-industry analogies rather than research-industry evidence, so they illustrate a mechanism rather than prove it operates here. The research Code faces the same mechanism: an industry that writes and polices its own rules has a standing incentive to police them gently.

Limitations

As of this writing, the Code's clearest limit remains its reach. ESOMAR runs real disciplinary machinery: complaints go to a Professional Standards Committee and, if they proceed, to a lawyer-chaired Disciplinary Committee, with sanctions ranging from a private warning to expulsion and publication of the member's name (ESOMAR, no date). That is more teeth than many voluntary codes carry, but it applies only to members. It has no hold on a firm that never joined. The fastest-moving problems addressed by the 2025 rewrite, autonomous AI respondents, synthetic-sample vendors, and industrial-scale survey fraud, are largely driven by suppliers outside the membership.

The vendor tier the Code most wants to reach is also the one that mostly grades its own work. Synthetic-respondent firms generate survey answers from models rather than people and largely validate themselves. Fairgen, one of the better-documented examples, points to some third-party checks alongside its own, but the sector as a whole reports its own accuracy. No industry-wide independent benchmark exists to test the claims (Fairgen, no date). The performance figures are self-reported, so they belong in the qualitative record rather than as hard statistics. A vendor saying its synthetic answers closely track human ones is a claim about its own product, not a measured fact a buyer can check.

The Code's reach is also asserted by its issuer. ESOMAR describes the Code as backed by many national associations across dozens of countries and taken up by large numbers of companies and individuals, but those counts trace to the body that publishes them, with no external register to confirm them. They are claims, not verified totals. The study that would settle the underlying question, whether the Code changes what members actually do, had not appeared at the time of writing. There is no independent audit of the 2025 Code's effectiveness or of member compliance since its release. The closest direct measurement of code compliance anywhere is the pre-2022, non-research work already noted.

ISO 20252 sits between the voluntary Code and hard law. It is a certifiable standard for market, opinion and social research that an outside body audits, so a firm can be checked against it rather than simply promising to follow it (International Organization for Standardization, 2019). A revision adding provisions on AI and automation went to public comment in 2025. It remains the auditable middle: more binding than a voluntary code because a third party inspects compliance, and less binding than a law because no government compels it. For a buyer who wants more than a promise, certification is the nearer thing to proof.

Open questions

The largest open question is whether the new duties can be enforced at all, because none had been enforced by the cutoff date. The only named ESOMAR ruling remains a two-year membership suspension, published with the individual named. It concerned recruitment fraud, a classic data-integrity failure, not a breach of the new AI, synthetic-data or disclosure duties (ESOMAR, 2025). The 2025 Code names those duties, but no public ruling had enforced one of them. That absence is not proof that the duties are unenforceable. It is what would be expected this soon after the 2025 release, and it is the clearest sign that the duties are still statements rather than tested rules.

Two smaller gaps follow. There is no post-2022 peer-reviewed study measuring research-industry code compliance specifically; an April 2026 targeted search returned nothing on point. The available academic backbone is very young. The soft-law papers cited carry no classified supporting or contrasting citations. In a literature this new, that is an absence of challenge rather than a wave of confirmation. Nobody has published the study that would test these claims against research-industry practice. Until someone does, the 2025 Code is a serious statement of intent whose real-world effect remains unmeasured.

So what

The 2025 Code is a genuine milestone, but its force stops at the membership boundary. For anyone who commissions or relies on research, the practical point is whether the supplier is inside that boundary.

For research practice

Treat the Code as a minimum standard and a shared vocabulary, not a guarantee. Use it and cite it in scopes of work. Its duties on disclosure, AI use and respondent care are the right ones. Treat a supplier's membership as a signal, not proof. Ask whether a practice serves the client's decision, not whether it looks compliant. A Code you can cite when a client asks how you handle synthetic respondents is useful. A Code you cite instead of doing the work is theatre. It fails when the results meet reality.

For companies

The Code protects you only if your supplier is a member and takes it seriously. The problems it newly names, such as synthetic respondents presented as real people or AI-generated answers passed off as fieldwork, are most likely from vendors outside the membership. The Code's disciplinary process cannot reach them. Ask who a supplier is accountable to. If a vendor says its synthetic respondents match human answers at a high rate, ask what was measured and who measured it. Vendors produce most published validation. No independent benchmark settles it yet. In commercial research, AI ethics are still decided in practice, not set in advance (Naz and Kashif, 2024). The buyer must ask.

For political parties

Question wording and sample choice change polling numbers. A party that relies on research is buying a picture of its own coalition. The Code binds reputable pollsters, but parties can buy from anyone. Synthetic samples and AI respondents are cheap, fast and private. That combination tempts a buyer to choose a supplier outside the Code, especially when the goal shifts from learning what voters think to producing a number that looks good. A vendor bound by nothing gives none of the Code's protections, however professional the presentation looks. The safeguard is to know whether your supplier is bound by anything at all. A poll built to reassure you is useless as intelligence. The electorate does not read the presentation before it votes.

For government and policy

Government meets this in two ways: as a research buyer and as a lawmaker. As a research buyer, government only benefits from the Code when the supplier is a member. Public work usually needs the stronger assurance of certification to ISO 20252. As a lawmaker, government should see the Code as the soft-law layer beneath binding rules such as the EU AI Act, covered in [M6-06]. Soft law and hard law are not substitutes (Xiao and Sun, 2025; Kim and Jon, 2026). Soft law guides early practice and changes quickly. Hard law supplies enforceable minimums and changes slowly. An auditable standard sits between them. Policymakers should treat the three as complementary layers covering different gaps, not as rivals where one makes the others unnecessary.

Case studies

An ESOMAR disciplinary ruling (2025). ESOMAR's enforcement is real and not merely nominal. A complaint is assessed by a Professional Standards Committee and, where it proceeds, heard by a lawyer-chaired Disciplinary Committee, with sanctions up to expulsion and publication of the member's name (ESOMAR, no date). The clearest recent example is a two-year membership suspension, published with the person named (ESOMAR, 2025). What makes it instructive is the subject: recruitment fraud, an old-fashioned data-integrity failure, not a breach of the AI or synthetic-data duties the 2025 Code introduced. The machinery works, and so far it has been pointed at a familiar kind of wrong. The new duties exist on paper and, as far as this research could establish, have not yet produced a public ruling of their own.

The Market Research Society of India adopts the Code (2025). In December 2025 the Market Research Society of India announced it would adopt the 2025 Code, with implementation from 1 April 2026 (Advanced Television, 2025). It is a clean example of how a voluntary code spreads, which is not by legislation but by national bodies choosing to endorse it and asking their members to follow. It is an equally clean example of the limit. The adoption binds the society's members. It does nothing about the firms in the same market that are not members, which are precisely the firms the new duty of care was most written to reach.

References

Advanced Television (2025) MRSI adopts global ICC/ESOMAR 2025 Code, 2 December. Available at: https://www.advanced-television.com/2025/12/02/mrsi-adopts-global-icc-esomar-2025-code/ (Accessed: 18 August 2026).

Alanoca, S., Gur-Arieh, S., Zick, T. and Klyman, K. (2025) 'Comparing apples to oranges: a taxonomy for navigating the global landscape of AI regulation', in Proceedings of the 2025 ACM Conference on Fairness, Accountability, and Transparency (FAccT '25), pp. 914–937. Available at: https://doi.org/10.1145/3715275.3732059 (Accessed: 18 August 2026).

Barda, K., Shaked, N. and Murtazashvili, I. (2025) 'The soft-law governance of digital ecosystems: comparing market-led and coordinated variants for AI', Journal of Cyber Policy, 10(2), pp. 158–176. Available at: https://doi.org/10.1080/23738871.2026.2614452 (Accessed: 18 August 2026).

Casey, D. (2023) 'Reproducing responsible gambling through codes of conduct: the role of trade associations and co-regulation', European Journal of Risk Regulation, 15(2), pp. 447–464. Available at: https://doi.org/10.1017/err.2023.50 (Accessed: 18 August 2026).

ESOMAR (no date) Professional standards. Available at: https://esomar.org/professional-standards (Accessed: 18 August 2026).

ESOMAR (2025) Ruling by ESOMAR's Disciplinary Committee. Available at: https://esomar.org/newsroom/ruling-by-esomar-s-disciplinary-committee (Accessed: 18 August 2026).

Fairgen (no date) Synthetic data validation: independent study. Available at: https://www.fairgen.ai/blog/synthetic-data-validation-independent-study (Accessed: 18 August 2026).

ICC/ESOMAR (2016) International Code on Market, Opinion and Social Research and Data Analytics. 4th edn. Available at: https://standards.esomar.org/ (Accessed: 18 August 2026).

ICC/ESOMAR (2025) International Code on Market, Opinion and Social Research and Data Analytics. 5th edn. Approved June 2025; released 29 September 2025. Available at: https://iccwbo.org/news-publications/business-solutions/iccesomar-international-code-market-opinion-social-research-data-analytics/ (Accessed: 18 August 2026).

International Organization for Standardization (2019) ISO 20252:2019 Market, opinion and social research, including insights and data analytics: vocabulary and service requirements. Available at: https://www.iso.org/standard/73456.html (Accessed: 18 August 2026).

Kaptein, M. and Schwartz, M.S. (2008) 'The effectiveness of business codes: a critical examination of existing studies and the development of an integrated research model', Journal of Business Ethics, 77(2), pp. 111–127. Available at: https://doi.org/10.1007/s10551-006-9305-0 (Accessed: 18 August 2026).

Kim, D. and Jon, W. (2026) 'How "hard" are hard laws? AI legislation, soft-law governance, and comparative lessons from South Korea and Japan', Computer Law & Security Review, 62, 106365. Available at: https://doi.org/10.1016/j.clsr.2026.106365 (Accessed: 18 August 2026).

Lexchin, J. (2023) 'Complaints about violations of voluntary and pharmaceutical industry-run medicine promotion codes', International Journal of Social Determinants of Health and Health Services, 53(4), pp. 518–527. Available at: https://doi.org/10.1177/27551938231165158 (Accessed: 18 August 2026).

Marchant, G.E. and Gutierrez, C.I. (2023) 'Soft law 2.0: an agile and effective governance approach for artificial intelligence', Minnesota Journal of Law, Science & Technology, 24(2), Article 4. Available at: https://scholarship.law.umn.edu/mjlst/vol24/iss2/4/ (Accessed: 18 August 2026).

Naz, H. and Kashif, M. (2024) 'Artificial intelligence and predictive marketing: an ethical framework from managers' perspective', Spanish Journal of Marketing - ESIC, 29(1), pp. 22–45. Available at: https://doi.org/10.1108/sjme-06-2023-0154 (Accessed: 18 August 2026).

Xiao, Y. and Sun, X. (2025) 'Integration of soft and hard laws: profiling legal protection for "AI for All"', International Journal of Digital Law and Governance, 2(1), pp. 223–252. Available at: https://doi.org/10.1515/ijdlg-2025-0003 (Accessed: 18 August 2026).

Explore the idea

Let’s talk

Invisible forces shape your world — until you hire Latenta®

Contact