Mike Taylor on Twitter pointed out that advertising apps in Google/Facebook world often use OAuth to gain the ability to spend advertising money on behalf of users without getting into trouble - I've added that counter-example as a note to my blog post here: https://simonwillison.net/2024/Aug/24/oauth-llms/