600+ members◆One Code of Practice◆ESOMAR◆GRBN◆APRC◆The Research Society◆Awards 17 Sep 2026
Research Association New Zealand
Why RANZ Membership Directory Standards News
Login Join RANZ

AI in market research: disclosure, transparency and data security

AI tools have entered research workflows faster than the guidance covering them. What agencies owe participants and clients on disclosure, and what handling data responsibly now requires.

Diagram showing six use cases of AI in market research: data collection and processing, consumer insight and segmentation, predictive analytics, sentiment analytics, competitor analytics and survey automation

AI has moved through research agencies faster than the guidance covering it. Tools that were novelties two years ago now sit inside everyday workflows: transcription, coding, summarising open-ended responses, drafting discussion guides, cleaning data, flagging fraudulent completes. Most of that is unremarkable and useful. The difficulty is that the obligations research bodies carry, to participants and to clients, were written for a world in which a human read every response.

Nothing in the Code of Practice changes because a model is involved. Informed consent, confidentiality, honest reporting and the separation of research from selling apply exactly as before. What changes is the number of places those obligations can quietly fail.

Where AI is actually being used

It helps to be specific rather than treating AI as one thing. In practice it turns up across the research cycle in six broad places.

Disclosure and transparency

The working principle is straightforward: anyone relying on the research should be able to find out how it was produced. That splits into two audiences.

Participants should be told when they are interacting with an AI system rather than a person. A chatbot-moderated interview, an AI probe on an open-ended question, or automated follow-up should be identified as such at the point of contact, not buried in a privacy policy. Where responses will be processed by AI tools, that should be covered in the consent information along with everything else that happens to their data.

Clients should know which parts of the work were machine-assisted and how the output was checked. A short methodological note is usually enough: the tools used, the tasks they performed, the human review applied, and any known limitations. Clients commissioning research are entitled to know whether a theme in the report came from an analyst reading transcripts or from a model summarising them.

Synthetic data deserves its own line. Model-generated respondents, simulated samples and AI-augmented datasets can have legitimate uses, but they must never be presented as, or mixed silently into, data collected from real people. If synthetic material appears anywhere in a deliverable, it should be labelled unambiguously.

Data security

Pasting participant data into a public AI tool is a disclosure to a third party. It should be treated with the same seriousness as emailing a raw dataset outside the organisation, because that is functionally what it is.

  • Know where the data goes. Which vendor, which jurisdiction, which sub-processors, and whether the Privacy Act 2020 obligations on cross-border disclosure are met.
  • Check the training terms. Consumer tiers of most tools reserve the right to train on submitted content. Enterprise agreements that exclude training and set retention limits are the minimum for anything containing participant data.
  • De-identify before, not after. Strip names, contact details and identifying context before material reaches a model. Free-text responses often carry identifiers the collection design never anticipated.
  • Set retention deliberately. Uploaded files, conversation logs and vector stores are all copies of the data, and all need a deletion path at project close.
  • Keep an approved tools list. Ad hoc adoption by individual staff is how most exposure happens. A short list of sanctioned tools with agreed settings prevents it.

Accuracy and accountability

Models fabricate confidently, reproduce the biases in their training data, and smooth over the minority view that a careful analyst would have flagged. None of that is a reason to avoid them; it is a reason to keep a human accountable for every claim that reaches a client.

Practically, that means verbatim quotes are checked against the source, AI-generated themes are validated against the underlying data, coding frames produced by a model are reviewed before use, and no finding is published that a named person cannot stand behind. Responsibility does not transfer to the tool.

A reasonable starting point

Agencies that have handled this well tend to have done four unglamorous things: written down which tools are approved and for what, added an AI clause to their consent and privacy information, agreed a standard methodological disclosure for client reports, and made one person responsible for reviewing the arrangement as the tools change.

That is a lower bar than it sounds, and it is considerably cheaper than explaining after the fact why participant data ended up in a training set.

Research Association New Zealand

The industry body for professional providers and users of research, data and insights.

Office@researchassociation.org.nz
About Who we areBoard & teamFellows & Life MembersGlobal affiliations
Membership Why joinMember directoryFind a companyApplication form
Standards Code of PracticeAI GuidelinesPolitical pollingComplaints
© 2026 Research Association New Zealand
ESOMAR GRBN APRC The Research Society