Most developers think about rate limits at API boundaries.

Protect the database.

Protect external services.

Protect model providers.

Protect public endpoints.