Forget about 8B people in this context. If you have 1000 microservices in the company and each has 100 rps, you are looking at ca. 100k rps to a Zanzibar-style system to authorize every request (not to authenticate a user).
I'd expect you to be able to give short-lived capability tokens to clients that each machine can verify down the stack without making new rpcs. This would avoid the fan-out of all the internal services.
Is it just to prevent abuse?
You need one capability token per principal and resource and perhaps access right.
In addition, yes - validating permissions on each request makes it so that you can revoke privilege(s) with immediate effect without needing a token to be invalidated.
[1] https://medium.com/building-carta/authz-cartas-highly-scalab...
BTW, didn't Google released something like it too early?
Makes me think of this: https://m.youtube.com/watch?v=y8OnoxKotPQ