It prevents the attack where thousands of users have thousands of long-forgotten keys lying around, and eventually one of them gets compromised months or years after it was last legitimately used. AKA a huge attack surface that can't reliably be culled, because you are effectively relying on users to be their individual CAs.
This particular attack took down my former organization once.