qualtranscribe logo

Transcription

Translation

qualtranscribe logo

8 mins

Understanding Artificial Intelligence Through the IRB Lens

You're using ChatGPT to help draft your IRB protocol. Or maybe Whisper for AI transcription of research interviews. Then it hits you: do I need IRB approval for this? The short answer: probably yes. The good news: it's not as scary as it sounds. This guide covers what researchers need to know about using AI tools ethically, getting IRB approval without unnecessary delay, and avoiding the mistakes that cause the most revision cycles.

A purple circular medallion with a scales-of-justice icon labeled 'IRB Review, AI Oversight' connects via dotted line to a white 'What IRBs look for in AI use' checklist card (4 Key Areas badge), on a gold gradient banner with a Research Ethics category badge

TL;DR

30 sec read

Here’s what you need to know

If you're using ChatGPT, Whisper, Claude, or any AI tool anywhere near human subjects data, it almost certainly needs to be disclosed in your IRB protocol. That's not a bureaucratic inconvenience, it's IRBs doing exactly what they're supposed to do: asking where participant data goes, who can access it, whether it can be deleted, and whether a human is verifying what the AI produced. Answer those questions clearly upfront and approval usually moves fast.

Best for researchers, compliance teams, and operations leaders evaluating transcription vendors.

Read the full guide ↓

Why AI Tools Trigger IRB Review (And Why That's Actually Good)

Artificial intelligence is moving faster than most IRBs are used to handling. AI tools offer real advantages for academic research: faster transcription, broader participant reach, quicker analysis of large datasets. They also introduce new questions around privacy, consent, and data security that a paper-based protocol never had to answer.

IRBs aren't anti-AI. They're anti-risk. When you introduce an AI tool into human subjects research, you're introducing new variables: where participant data goes, who or what has access to it, whether it can be permanently deleted, and whether the AI might introduce bias into your findings. These aren't hypothetical concerns. They're the same questions an IRB would ask about any new methodology, applied to a genuinely new set of tools.

When Does "I'm Just Using ChatGPT" Trigger IRB Scrutiny?

Almost always. Most researchers think of AI tools as "just software," the same category as Microsoft Word or Excel. But once an AI tool processes human subjects' data, it becomes part of your research methodology, and that's what triggers review.

Using AI transcription tools like Whisper or Otter.ai creates a verifiable record from private, identifiable data, and many free AI transcription services use uploaded audio to train their models. Analyzing interview transcripts with ChatGPT or Claude means a third-party model is performing analysis on identifiable human subjects data, often through an API that sends that data outside your institution's control. Using AI to generate synthetic data carries its own risk: a model can produce realistic but false information, which creates problems if it's ever mistaken for genuine participant data. Using AI to screen or recruit participants means an algorithm is making decisions about real individuals, with the same bias risks any automated screening carries. And using AI to "anonymize" data is worth extra scrutiny, since language models frequently fail at true de-identification, which is why most IRBs still expect human verification of anything a model claims to have anonymized.

The Four Questions Every IRB Will Ask

When you submit a protocol involving AI, expect these lines of inquiry.

Human subjects protections. Will the AI tool directly interact with participants, or only analyze data after the fact? Even AI that touches only recordings or transcripts can count as human subjects research if the data contains identifiers. Be ready to explain exactly what data the AI sees, whether identifiers are present, and how outputs get verified by a person.

Data privacy and security. Where is participant data stored? Who has access, including the vendor's own employees? Does the vendor store, copy, or reuse your data? Is it encrypted in transit and at rest? Does the tool comply with HIPAA, FERPA, GDPR, or CCPA where relevant? This is usually the section that determines how fast your protocol moves, and it's also why many researchers choose a transcription service with documented compliance already in place rather than assembling that documentation themselves for a general-purpose AI tool.

Algorithmic transparency. What does the AI actually do with the data, and what are its limits? How are errors caught and corrected? Are outputs reviewed by a human before they're used in the analysis? This matters especially in qualitative research, where nuance, emotion, and context carry real analytical weight.

Risk of bias. How was the model trained, and could it produce skewed results for certain demographic groups? AI models can inherit the biases of their training data. Speech recognition trained mostly on American English, for instance, can perform noticeably worse on participants with accents or non-native speech patterns, which risks quietly excluding certain voices from the research.

What Tends to Work and What Doesn't

The scenarios below are composites drawn from common IRB feedback patterns, not documented individual cases, but they reflect the kinds of issues that come up repeatedly.

A researcher wanting to use an LLM to code open-ended patient feedback typically runs into trouble if there's no Business Associate Agreement with the AI vendor and the consent form never mentioned AI analysis in the first place. Switching to a deployment that doesn't send data to an external server, or adding a signed BAA, usually resolves it in a single revision.

A researcher using an AI tool for transcription and summarization of focus group audio tends to move through review smoothly when the consent form explicitly names the AI tool being used and the deployment keeps data within a private, non-training instance.

A researcher relying on a free AI transcription API for interview audio often gets an initial rejection specifically because the free tier sends audio to external servers with unclear retention terms. Switching to a self-hosted model, or to a human-verified transcription service that doesn't train on uploaded data, tends to resolve the concern.

The pattern across all three: transparency in the consent form plus a clear answer about where data goes and whether it trains anything gets protocols through review. Silence on either point is what causes delay.

The Most Common IRB Questions About AI

A few questions come up in almost every protocol involving AI tools, and it's worth having answers ready before you submit.

Does your AI provider use uploaded data to train its algorithms? Check the vendor's terms of service directly. Many free tiers do use uploaded data for training; enterprise or paid tiers often exclude it, but that needs to be confirmed, not assumed.

Can participant data be permanently deleted? Document the vendor's retention and deletion policy, and get it in writing if your IRB requires that level of documentation.

How will you anonymize data before AI processing? Removing names alone usually isn't enough. Contextual details in an interview can identify someone even with names stripped out, which is why de-identification generally needs a documented process, not just a find-and-replace pass.

Will humans verify all AI-generated outputs? The answer here should always be yes, with a clear explanation of who does the verification and what their qualifications are.

Can participants opt out of AI analysis? This needs to be an option in your consent form, with a workable alternative process for anyone who opts out.

How will you handle incidental findings? If an AI tool flags something unexpected, like a potential mental health indicator buried in an interview transcript, you need a plan in place before that happens, not after.

Your IRB Approval Checklist for AI Tools

Before you submit a protocol involving any AI tool, confirm you can check off each of these:

  • You've identified every AI tool touching participant data, including transcription, analysis, or screening tools

  • Your consent form names the AI tools being used and explains what they do

  • You know whether each vendor uses uploaded data for model training, and have it documented

  • You have a signed Business Associate Agreement wherever HIPAA-covered data is involved

  • You've described your human verification process for AI-generated outputs

  • Your protocol addresses data retention, deletion, and who has access at each vendor

  • You have a plan for incidental findings an AI tool might surface

  • Participants have a genuine opt-out path from AI-assisted analysis

IRBs Support Innovation When It's Done Responsibly

IRBs want your research to succeed. They aren't trying to block AI transcription, machine learning analysis, or automated data collection. They're making sure human subjects stay protected, data is handled securely, consent is genuinely informed, and privacy risks are minimized before the study moves forward.

Protocols that face delays usually share the same pattern: researchers assumed an AI tool didn't need disclosure, underestimated the data privacy questions, didn't verify the vendor's security practices, or couldn't explain their human oversight process. Address those four things directly and most protocols move through review without much friction.

Why Human Oversight Still Matters

AI is powerful, but it isn't infallible. A person still needs to catch transcription errors, correct misunderstood context, and recognize when a cultural or linguistic nuance got flattened by the model. Ethical judgment, recognizing bias, handling sensitive disclosures appropriately, making the nuanced calls a model can't make, still requires a human in the loop. So does interpreting tone, sarcasm, or ambiguity correctly, and so does the actual regulatory work of documenting your process and maintaining an audit trail an IRB can review.

Understanding AI through the IRB lens isn't just about clearing a compliance hurdle. It's about building a research process that holds up, for your participants and for your findings.

Need transcription that's already built around IRB-compliant, human-verified workflows? Get started here.

FAQ

Do I need IRB approval just to use ChatGPT for brainstorming my research questions? Probably not, if no participant data is involved. The moment an AI tool touches identifiable human subjects data, whether that's a recording, transcript, or survey response, disclosure is expected.

Is human-verified transcription automatically IRB-compliant? Not automatically, but a documented, human-reviewed workflow with clear data handling policies is generally much easier to describe in a protocol than a general-purpose AI tool with unclear training practices.

What's the difference between a BAA and a data processing agreement? A Business Associate Agreement applies to HIPAA-covered data in the US. A data processing agreement is the GDPR equivalent for personal data tied to EU participants. Both document how a vendor is allowed to handle the data.

Can I use AI transcription and still meet IRB requirements? Yes, if the tool doesn't train on your data, you can document its security practices, and a human verifies the output before it's used in analysis.

What should my consent form say about AI use? Name the specific AI tools involved, explain what they do with the data, and confirm that identifying information will be handled according to your stated retention and deletion policy.

Related Reading

External resources: OHRP Human Subject Regulations Decision Charts, Read the Belmont Report

Turn your recordings into analysis-ready transcripts.

Human Transcription

Clean verbatim and full verbatim transcripts, delivered by specialist transcriptionists

AI Transcription

Instant Draft powered by AI, with Smart Insights for analysis-ready output

Translation Services

Accurate translation across 99+ languages for multilingual research workflows

Keep reading

Related articles

A raw German audio waveform passes through a GDPR checkpoint gate, German flag in and EU flag out, into a compliant transcript waveform, beside a pass/fail panel on data agreements, EU storage, native speakers, and erasure rights.

GDPR-Compliant German Transcription: What EU Research Teams Need to Know

GDPR has issued over €7.1 billion in cumulative fines since 2018, with €1.2 billion issued in 2025 alone, according to the DLA Piper GDPR Fines and Data Breach Survey published in January 2026. Enforcement is active, consistent, and specifically focused on data processing practices that research institutions treat as routine. Using a transcription service without a Data Processing Agreement in place, routing recordings through servers outside the EU without appropriate safeguards, or failing to specify retention and deletion timelines for audio files are all compliance failures that regulators have acted on. For German research teams, this isn't a future risk. It's an active one.

Read article

A reel-to-reel tape deck from 1974, its spools connected by looping tape, beside a checklist on what accuracy protects in oral history transcription, dialect, pauses, names, and cultural consent

Oral History Transcription: How to Preserve Community Voices Accurately

Oral history gives voice to people and communities whose experiences rarely make it into official records. An elder describing a neighborhood before it was demolished. A civil rights witness recounting what she saw. A craftsperson explaining a technique that has never been written down. These recordings are primary sources. How they get transcribed determines whether they survive intact as historical record or get quietly reshaped by someone else's sense of how people should speak on the page. The stakes are different here from market research or academic interview data. A poorly formatted research transcript wastes coding time. A poorly transcribed oral history misrepresents a person's voice to anyone who reads it for the next hundred years.

Read article

A farmer's quote on flooded seed stock, tagged as it moves from field interview to funding-proposal evidence — how NGOs turn field interviews into actionable dat

Transcription for NGOs: How Development Organizations Turn Field Interviews Into Actionable Data

Development organizations spend months designing studies, recruiting participants, training field teams, and traveling to remote communities to collect qualitative data. The recordings that come back from that work are often the richest, most direct evidence of program impact that exists. They contain beneficiary voices in their own words, unprompted observations about what's working and what isn't, and context that no survey instrument can capture. Then those recordings sit on a laptop while the donor report deadline approaches and nobody has figured out what to do with them. Transcription is the step that most development organizations treat as an afterthought and then scramble to fix at the end of a project. This post makes the case for treating it as infrastructure instead.

Read article

qualtranscribe logo