Replying to
@argv_minus_one@mastodon.sdf.org @agowa338@chaos.social @collective_truth@mastodon.social @hotelzululima@mastodon.social @freya@social.highenergymagic.net https://source.android.com/docs/security/features/authentication/rate-limiting#stronger-default-rate-limiting-policy shows the recommended rate limiting policy for Android 16 QPR2 and later. It was shipped for the Pixel secure element firmware with the initial Android 16 QPR2 release to replace the previous much less aggressive rate limiting.
It's also worth noting the secure element only accepts firmware updates after Owner user successfully authenticates which is a feature referred to as insider attack resistance.