Rate limiting now isolates per API consumer: per key, per user account, per IP. One bad actor can't exhaust shared quotas. Malicious behavior becomes easier to identify. Observed threshold: 100 requests per minute for short-duration abuse prevention. Global limits are out.