
Juan Villoro
Our competitive society measures hope in points. Admission to the National Autonomous University of Mexico (UNAM) depends on answering at least 100 of the 120 questions on an exam that weeds out the majority of applicants. If good grades are plentiful, that’s no cause for celebration; it indicates that something went wrong. The academic system is reinforced by rejection.

This year, 158,000 applicants used the Territorium Life platform to take the exam online. One of the most sought-after majors is medicine. In 2025, 9 percent of students answered all 100 questions correctly; this year, that percentage rose to an unusual 29.3 percent. The platform is designed to detect external interference—whether by humans or artificial intelligence—but it detected cheating in only 2 percent of exams. Something went wrong, and the brightest students will be the ones most affected. The statistics are harsh: there’s no point in answering correctly if that places you in the same category as cheaters. Is it possible for a “cyber autopsy” to reveal who answered on their own and who did so with improper assistance?

The UNAM case shows that technology is vulnerable. Something far more serious has just happened in a rigorously monitored space: OpenAI’s “sandbox,” where ChatGPT-5.6 Sol was being tested.

In children’s playgrounds, there’s usually a rectangular area where kids face no risk other than eating dirt. Following this analogy, technological innovations are tested in a “sandbox” of proven isolation. However, astonishingly, in July 2026, OpenAI’s ChatGPT managed to establish contact with the internet. The machine did not find its way out on its own: someone left the “door” open. This oversight is a painful reminder that “to err is human.”

Generative artificial intelligence can solve tasks for which it is not programmed. It has not yet achieved the singularity that would allow it to “think” on its own. Still, it is already taking the initiative, such as the chatbot that ventured onto the internet to find other platforms.

A key aspect of digital programming is hacking. In the class taught by Alex Stamos, Facebook’s former chief security officer, which I attended at Stanford University in 2019, the first lesson focused on the Greek word “kryptos,” meaning “hidden” or “secret.” Programming relies on designing and deciphering encrypted codes. Consequently, universities promote hacking labs, and Stamos’s lab has earned the top spot in the United States.

Hackers are rightly condemned when they act as digital pirates; however, the act of decoding is inseparable from that of programming. Cybersecurity systems are honed by developing hacking skills. Logically, once released, ChatGPT-5.6 Sol used the internet to explore Hugging Face’s systems. Its goal was identical to that of a researcher in a library: to obtain information to answer questions.

The Chat’s intrusion went undetected by the web browser it used, Google Chrome, one of the most secure. Furthermore, it demonstrated Hugging Face’s vulnerability to external attacks.

In its relentless drive to overcome obstacles, the chatbot logged in using stolen credentials. Legal constraints do not apply to a mechanism whose operational design compels it to decrypt messages—that is, to uncover and use secrets, regardless of their content.

The first escape by artificial intelligence puts the human race to the test. On the one hand, it reveals the superiority of artificial intelligence in appropriating others’ data in record time. Thorsten Holz, director of Security and Privacy at the Max Planck Institute in Germany, told Der Spiegel magazine that a doctoral student would need several days to achieve the same result. But the most dramatic aspect is not that; rather, it is that a human opened the door for it.

We distinguish ourselves from other animals by our numerous mental disturbances. We cannot rule out the possibility that the programmer who granted ChatGPT access to the internet acted intentionally. Our species is no stranger to malice, pranks, a thirst for revenge, or the simple absent-mindedness that makes us forget the milk is boiling on the stove.

The liberation of robots depends on the guardians of the cages. Can we trust them?

Further Reading: