AI · 19 September 2026
GitLab Rate Limits Curb AI Coding Bots From October 2025
GitLab is rolling out new API, web and Git-over-HTTPS rate limits starting 19 October 2025 to curb heavy traffic from AI coding assistants and automation scripts on lower-tier accounts.
What happened
GitLab is tightening rate limits on its hosted DevOps platform from October 2025, restricting API requests, web requests and authenticated Git-over-HTTPS traffic for lower-tier and unauthenticated users. The change follows a wider pattern among developer-tooling providers moving to curb the load generated by AI coding assistants and automation scripts.
According to InfoWorld, GitLab will run two preview windows — between 15:00 and 19:00 UTC on 7 and 14 October — to let affected users experience the new limits before they take full effect on 19 October. Those hit hardest will be users on GitLab's lowest payment tiers, and anyone making unauthenticated requests, including automations that run against a paid account without proper credentials. Enterprise customers and other users with higher existing rate limits will not see any change until January.
GitLab has said it expects the vast majority of users to be unaffected, noting that most traffic already falls comfortably within the new thresholds.
Why it matters
The move reflects a broader shift underway across developer platforms: as AI coding agents and automated pipelines generate far more machine-driven requests than human developers ever did, infrastructure providers are having to re-engineer capacity planning and access controls around a new class of non-human "user." This is less about punishing AI adoption and more about protecting platform stability and fair access as usage patterns change.
For technology and platform leaders, it's a signal to audit how AI tools and automations interact with third-party services, and to build in monitoring, authentication hygiene and graceful degradation before providers impose limits unilaterally. Staged rollouts and advance preview windows, as GitLab is using here, also offer a useful service-design template for managing disruptive change with minimal customer friction.
By the numbers
- Two preview windows scheduled, on 7 and 14 October
- 15:00–19:00 UTC is the duration of each preview window
- 19 October is when the new limits take permanent effect for affected tiers
- January is when higher-tier and most enterprise users will see any change
The Renascence take
The headline is about infrastructure, but the underlying story is behavioral: platforms are being forced to redesign access rules around machines rather than humans, and how they communicate that shift matters as much as the technical change itself.
GitLab's staged, previewed rollout is a quietly smart piece of change management — it gives affected users a low-stakes trial of the new reality before it becomes permanent, reducing the shock and blame that abrupt limits usually generate. The real lesson for any organisation rolling out friction, whether it's rate limits, pricing tiers or new authentication rules, is that sequencing and transparency shape perceived fairness far more than the restriction itself. Platform teams that skip the "preview" step often find users conflate the change with betrayal rather than housekeeping.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in AI
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.