Blog  / considered ai

The AI didn't cheat: Mexico's online admissions exam

UNAM spent 41.8 million pesos policing its first online exam. It failed. But blaming artificial intelligence is the easiest way to review nothing.

StrangeDaysTech Team

July 25, 2026 · 20 min read

The short version

  • Mexico’s National Autonomous University (UNAM) paid 41.8 million pesos (about US$2.4 million) to administer and invigilate some 158,000 online exams: roughly 264 pesos — about US$15 — per candidate.
  • The contract required a notary public to load the exam questions onto the platform, and one human proctor per 150 screens while the exam was being taken.
  • The cutoff for Medicine at the main campus went from a historical average near 60 correct answers to 117 out of 120. Some 5,000 candidates with scores that would have won them a seat in previous years were left out.
  • If the fraud happened in real time rather than through a leak of the exam, nobody breached the contract. And then there is no one to bill.

This piece is about Mexico, but the mechanism is not. UNAM is the country’s National Autonomous University: the largest in Mexico, among the largest in Latin America, and free at the point of entry. Admission runs through a single multiple-choice exam with a fixed number of seats per program — so the passing score isn’t set in advance, it emerges from whoever happens to sit the exam that year. Hold on to that detail; the whole story turns on it.

Over the past few days one sentence has been repeating itself in headlines, over dinner tables and down timelines: artificial intelligence cheated on UNAM’s entrance exam.

The sentence is worth pausing on, because it’s false in a literal, boring sense and very revealing in another.

Artificial intelligence did not register for the exam. It did not decide to move the test from a lecture hall to a living room. It did not draft the sixteen security mechanisms of a forty-one-million-peso contract. It did not determine that one human proctor per one hundred and fifty candidates would do. It did not record TikTok tutorials explaining where a webcam’s blind spot sits. It did not buy a 360-degree camera or hide a black earbud under long hair. It did not open an account to sell answers for fifteen hundred pesos. It did not file the criminal complaint or order the enrollment of thousands of students suspended three days before it was due to begin.

A person did every one of those things. Some of them with a name and a job title. Others with a credit card and a decision made in the small hours of the Sunday of the exam.

That the public conversation organized itself around a subject that doesn’t exist — “the AI” — is no semantic accident. It is enormously convenient. If the culprit is a technology, then the failure is a fatality, something that happened to us, like a frost or an earthquake. Nobody has to explain why what was decided was decided. Nobody has to give back a peso. And above all: nobody has to revisit the underlying idea, which is the thing that actually broke.

What we know

The facts, briefly, because it helps to have them in order.

For the first time in its history, UNAM ran its undergraduate entrance exam entirely online. Around 158,000 candidates sat it across three weekends in May and June. On July 3, before releasing results, the university filed a criminal complaint against individuals and companies that had allegedly sold fraudulent services to families. Results came out on July 17: some 21,962 seats awarded, more than 133,000 candidates left out. About 2% of the exams — some 3,174 — were voided for conduct contrary to the terms of the call.

Then the data started talking.

Independent analysts noticed that the 2026 distribution of scores looked like no previous year. In Medicine at the Faculty of Medicine, the historical average had hovered between 59 and 62 correct answers from 2021 to 2025; this year it jumped to 78. The cutoff — the score of the last candidate to win a seat — reached 117 out of a possible 120. At UNAM’s Zaragoza and Iztacala campuses, medians rose by 27 and 28 correct answers respectively. The number of candidates scoring 110 or above grew almost sixfold over the previous year.

And the figure that should hurt most: an analysis by ITAM, a private university in Mexico City, estimated that close to five thousand candidates were left out despite scores that in previous years would have won them a seat. Around 3% of everyone who took part. These are not detected cheats. They are people who studied, answered well, and lost their place because the floor moved underneath them.

On July 21 the rector ordered a report and convened a technical commission. On July 24, the university suspended document submission and enrollment for the entire incoming class, which was due to start on the 27th.

What it cost, and what that bought

This is where the case stops being a story about dishonest students and becomes something else.

The university publicly justified the change of format on other grounds: widening the geographic reach of the process, cutting travel costs for candidates from outside Mexico City, and reducing the pollution generated by printed materials and mass movement. These are reasonable arguments, and the second one is true: it saved many families transport, lodging and a lost day of work. But there is a figure that formed no part of the justification and is worth keeping to hand: compared with the in-person operation of 2025, the online format saved the institution 7,362,000 pesos (about US$421,000).

UNAM contracted the Mexican company Territorium Life to run the platform. The base contract was 40,703,000 pesos (about US$2.3 million) for a minimum of 154,000 remote exams, with 264 pesos for each additional test. The total paid: 41,868,156 pesos.

That is roughly 264 pesos — about US$15 — per candidate invigilated.

What did those 264 pesos buy? Sixteen agreed security mechanisms: real-time facial recognition against the official photograph; AI monitoring of noises, voices, the presence of third parties and prohibited objects; blocking of external browsers, of platforms such as ChatGPT, of the copy function, of secondary screens and of screen recording; encryption of the data. Plus human validation: 74 proctors, one per 150 candidates.

Stop there. One proctor per 150 people sitting an exam simultaneously.

That number, on its own, explains almost everything.

When UNAM came out to clarify that artificial intelligence does not cancel exams automatically, that it only raises alerts and that the final decision always rests with university staff, it said something technically true and practically empty. Nobody supervises 150 live video streams. What a human proctor does at that ratio is work through the queue of incidents the machine has already decided to show them. Human review doesn’t correct the system’s judgment: it ratifies it faster.

And out of that come the two simultaneous failures, which look contradictory but are the same one.

On one side, the system didn’t see what it didn’t know how to look for. The guides that circulated on TikTok before the exam described no sophisticated exploit: they described analog detours around a digital perimeter. A second phone in the camera’s blind spot. A black earbud hidden under long hair. Screen-sharing over Discord so someone else could dictate the answer. A 360-degree webcam that kept the candidate permanently in frame while another person answered off-camera. None of that requires hacking the lockdown browser. It only requires understanding that a front-facing camera faces front.

On the other, the system did aggressively escalate what it knew how to score. Dozens of candidates reported cancellations over power cuts, dropped internet, street noise, a family member walking past behind them. A public petition argued that the test was assessing the material conditions of the home rather than knowledge. That same complaint had already surfaced in the upper-secondary entrance exam the previous November.

Put the two halves together and the uncomfortable conclusion follows: the surveillance wasn’t insufficient. It was precise in the wrong dimension. It was relentless about noise in the room and blind to the 360-degree camera. And that asymmetry isn’t random: it punished the candidate sitting the exam in shared housing and waved through the one who could buy equipment.

There is a detail in the record that makes the asymmetry almost didactic. The exam is designed by UNAM’s own assessment and educational development office, and to load the complete versions onto the platform the contract required the simultaneous presence of a notary public, staff from Internal Audit, a legal representative of Territorium and another from the university’s registrar. The entire question bank had to travel, be stored and be processed under advanced encryption, accessible only to authorized operators.

A note for readers outside civil-law countries: a Mexican notario público is not the rubber stamp the word suggests in English. It is a law graduate holding a state-issued license, and their attestation carries legal force in itself. Requiring one is not a formality — it is the heaviest evidentiary guarantee the system offers.

Which is to say: a notarial ceremony to protect the document, and one proctor per one hundred and fifty screens to protect the exam.

That imbalance isn’t negligence, it’s an inherited threat model. For decades, the only way to beat a mass exam was to obtain it beforehand: steal the envelope, buy off the printer, leak the bank. The notary, the encryption and the chain of custody were built against exactly that, and they worked — as far as anyone knows, nobody has shown that a single question leaked. But the 2026 attack didn’t need advance knowledge of the exam. It happened in real time, inside the candidate’s room, with the clock running. All the security imagination was aimed at the wrong asset.

The contractual price of failure

One number is missing.

The contract provides that, if failures or negligence are confirmed in any of the sixteen mechanisms, or if a leak of the question bank is established, Territorium Life pays a penalty of 10% of the total: up to 4,180,000 pesos (about US$239,000).

Put it next to the rest. The total failure of the admissions process of the largest public university in the country is priced, contractually, at 4.18 million pesos. The saving that partly motivated the change of format was 7.36 million. Which is to say: even paying the penalty in full, the operation still closes in the black for the institution.

This is not an accusation of bad faith against anyone. It is a description of how the incentives were arranged. The real cost of what happened is absorbed neither by the university nor by the vendor. It is absorbed by the five thousand displaced candidates, who signed no contract and have no penalty clause to invoke.

And then comes the turn that closes the argument. Asked by the newspaper El Sol de México, Territorium replied that it could not validate the legal interpretation being put to it, and maintained that the platform operated as foreseen throughout the online administration, as it had in the processes it has run for UNAM since 2024.

The interesting part is that everything suggests this is true. And that is exactly the problem.

A contract can only punish the breach of a specification; there is no clause for an obsolete specification. Had the question bank leaked, there would be an identifiable party at fault and the 4.18-million penalty would be enforceable. But if what happened was real-time assistance from off-camera — which is what all the available public evidence points to — then the facial recognition recognized faces, the browser blocked browsers, the encryption encrypted, the seventy-four proctors worked their alerts, and nobody breached anything at all. The system did precisely what it was asked to do.

Five thousand people were pushed out of a process in which, legally, everything worked.

There’s the gap, and it isn’t a philosophical riddle about the nature of artificial intelligence. It is a problem of contract design: nobody wrote the clause covering what actually happened, because nobody imagined it. The absence of a culprit doesn’t mean there were no decisions. It means the decisions were taken looking at the previous risk.

And this is where we come back to the beginning. Saying “the AI cheated” erases exactly this part: the contracts, the margins, the supervision ratios, the purchasing decisions. The tool is the perfect alibi because it holds no assets, has no tax domicile and cannot be summoned to appear.

The first real problem: how we assess

The intuitive reaction is to ask for more locks. Better proctoring, more AI, more sensors, a more secure browser. It’s the wrong reaction, and you don’t have to take our word for it: the industry that sells the surveillance says so itself.

Sector analyses acknowledge that automated invigilation was designed for visible, definable behaviors — switching tabs, pulling out a phone, another person on camera — and that AI assistance frequently leaves no visible trace at all. They also acknowledge that once a cohort of students has watched videos on “how to beat Proctorio”, the deterrent value of a camera pointed at your face has evaporated. The conclusion they draw is the same one we draw here: redesign the assessment, not the surveillance.

Some universities are already doing it. The University of Bath is dropping its old scheme this cycle for a “two-lane” approach developed by the Association of Pacific Rim Universities: open assessments, where the use of generative AI is optional or even integral to the exercise — because in working life you are expected to use it well — and closed assessments, in person, invigilated, time-bound. Cardiff is considering adopting it. The point of the model isn’t nostalgia for paper: it’s to stop pretending that a task the machine solves in seconds still measures something about the student.

It’s also worth looking at the costs of the opposite path. In Australia, rising cases of alleged AI misconduct led one university to log thousands of cases, a substantial share of which were ultimately dismissed. Automated punitivism doesn’t just fail to catch people: it produces its own victims and erodes the trust it claimed to protect.

A 120-question multiple-choice exam, taken remotely, measures something the technology now does better than almost any 18-year-old. This isn’t a discipline problem. It’s a design problem.

The second real problem: the one that’s harder to admit

It’s very easy to say “cheating”. It’s a word that sorts the world fast: there are honest people and there are cheats, there is merit and there is theft. And that is exactly why it works so well as a plug.

Because underneath it sits a fact no technical commission will change: UNAM’s own rector has noted that around 200,000 upper-secondary graduates a year fail to find a place at any university. This year, in the Biological and Health Sciences area, only 6.6% of those who sat the exam got a seat. Medicine at the main campus had 16,411 candidates for 176 places.

A funnel like that is not a measuring instrument. It is a rationing mechanism arriving at the end of a deeply unequal twelve-year trajectory, asking an eighteen-year-old to make up in three hours what the system failed to give them over a decade. When the margin between getting in and not is three correct answers, the difference is rarely explained by effort: it’s explained by the high school you were able to attend, the prep course you were able to pay for, the room of your own you were able to study in.

And it is worth saying plainly: that funnel is a public policy decision, not a fact of nature. Between the 2000-2001 and 2018-2019 academic years, UNAM’s internal demand — from its own high schools, whose graduates enter through guaranteed admission — grew by around 54% and was met in full, year after year. Over the same period, external demand quadrupled: from some 64,000 to more than 261,000 candidates. Institutions were created, but none at the scale of the demand nor with enough standing to redirect it. The bottleneck didn’t happen: it was administered.

This year the arithmetic says it without ornament. Through the competitive exam, 21,962 people got in. Through guaranteed admission, 28,151. More first-year students were admitted without sitting this exam than through it. This is no reproach to them: guaranteed admission is legitimate and the university has every right to educate its own graduates. It’s an observation about where access is actually decided. For most people, the door closed three years earlier, at fifteen, in a different exam, when places were allocated at the high schools that later grant automatic entry. The competition everyone is talking about this week is the second round of a distribution already made.

And this year, on top of that, the exam moved into the home. That meant real savings for many families — transport, lodging, a lost day of work — and it also meant the home entered the assessment. Bandwidth, the stability of the electricity supply, silence, the possibility of having a room to yourself for three hours: all of it stopped being context and became a measured variable. Whether that was fair is arguable. What isn’t arguable is that it is distributed exactly like income.

Against that backdrop, individually reproaching those who didn’t overcome it — and celebrating the exceptional cases as proof that “it can be done” — is a way of shouting very loudly so as not to listen. That genre of story, the young person who studied in impossible conditions and got a perfect score, circulates precisely because it is rare: if it were representative it wouldn’t be news. And almost always, when you read the full piece, the detail that made it possible appears. A mother who held the household together alone so he wouldn’t have to work. A teacher who lent a computer. An uncle with internet. What appears, in short, is the scaffolding. What we celebrate as pure merit is usually real merit plus scaffolding most people don’t have. Using those stories as a yardstick for everyone else isn’t demanding: it’s an elegant way of changing the subject.

But the other half has to be said, or the argument turns complacent: cheating didn’t level the floor either. It required a second screen, an extra camera, someone available on the other end, fifteen hundred pesos (about US$86) for a Telegram account. It was technological capital competing against educational capital, and technological capital is inherited too. It didn’t correct the inequality: it changed the instrument. Whoever couldn’t afford the webcam stayed just as excluded, only now under suspicion as well, and with the certainty — statistically grounded, this time — that the seat they didn’t get went to someone who could pay for it.

That is the bitterest reckoning of the week. Not that some young people cheated. That a system incapable of offering enough places ended up teaching an entire generation that inequality is compensated for by buying better equipment.

The new floor

We’ll close with what worries us most, and we put it forward as a hypothesis, not a fact.

UNAM’s cutoff is not a requirement set in advance. It is the score of the last candidate to win a seat. Which is to say: the threshold is produced by the cohort itself. With a fixed number of places, someone who cheats doesn’t “steal a seat” in the abstract: they mechanically push the floor upward for everyone else. It is a direct, quantifiable transfer, not a diffuse moral failing.

Now: that inflated number has already been published. It is already in the minimum-score tables that commercial prep academies circulate as study targets. In a few months, a young person who wants to study Medicine will open a guide and read that they need 117 out of 120.

If nothing changes, that figure will tell them two things at once. That the legitimate target has risen to somewhere nearly unreachable. And that last year there was a shortcut that worked. The rational conclusion for someone with no margin for error is obvious, and it doesn’t depend on their character. That is how a loop is built: cheating moves the cutoff, the cutoff is published as a target, the target makes cheating compulsory. Each iteration degrades a little further the relationship between students and the institution that was supposed to educate them.

Faced with that, UNAM has four ways out and none is free. Validating the results enshrines the inflated cutoff and confirms that the shortcut worked. Voiding selectively is what has already been done, and it is precisely what produced five thousand displaced candidates without correcting the statistical shift. Re-running the exam in a secure environment costs a fortune, punishes those who did nothing wrong as well, and resolves nothing about next year. Redesigning the assessment is the only thing that addresses the cause, and the only thing that doesn’t fit in the August calendar.

That a technical commission exists, and that enrollment is on hold, suggests the first option has already been ruled out in practice. Good.

What remains to be seen is whether the diagnosis stops at the vendor — a 4.18-million-peso penalty, a reworked contract, more locks next year — or reaches the level where the failure actually lies. Because the technology will fail again; it always does, and always for the same reason: someone decides what to look at and necessarily leaves something out of frame. The question that matters isn’t how to invigilate 158,000 people better.

It’s why we still allocate a generation’s future with an instrument that artificial intelligence solves in seconds, and what kind of learning would be worth measuring instead.

And while we’re here, let’s be precise about the accounting, because the argument of this piece is not that nobody is responsible. It is exactly the opposite.

Responsible is whoever copied knowing they were copying. Responsible is whoever recorded the tutorial and whoever charged fifteen hundred pesos for a set of answers. Responsible is whoever decided that an exam determining entire trajectories could be administered remotely. Responsible is whoever signed off on sixteen locks and one proctor per one hundred and fifty screens. Responsible is whoever priced total failure at ten percent of the contract. And responsible is the higher-education policy of five consecutive federal administrations, across three different parties, which watched demand quadruple and responded by creating institutions nobody perceived as substitutes for the ones already full.

The list is long and every line has a name, a job title or a tax ID. None of them reads “artificial intelligence”.

A statistical model does not appear before a judge, does not give back a peso, does not resign, does not owe anyone an explanation. That is why it makes such a comfortable culprit. And it’s why we will go on reading it in headlines every time a system designed by people does exactly what those people asked it to do.

Enrollment is due to begin on July 27. It is on hold, and nobody has said when it resumes. When that queue finally forms, close to five thousand young people who answered correctly won’t be standing in it.

No algorithm took them out.


Notes and sources

Figures current as of July 25, 2026. UNAM’s technical commission had not published its report at the time of writing. Peso amounts are converted at 17.48 MXN to the US dollar, the rate on July 24, 2026. Most sources are in Spanish.

considered ai education public policy