Earlier quoted context omitted.
"correct horse battery staple" doesn't fit in 16 characters, and has has much better recall than basically all similarly-secure passwords that do. Longer passwords let you optimize passwords for ease of recall and security, rather than fitting in arbitrary requirements.
Even though that phrase password is 16 characters long, it has the same entropy as a 9-10 letter long alphanumeric random password (according to KeePass' generator). I agree that it's easier to recall, but it's half as secure as a properly random 16 character one.
There were no duplicates in any of the 50 sets. (About a week's runtime on a fairly modest Intel processor.)
Given that 100m accounts is a fair fraction of the world's active computer users, that's a pretty good start.
(There are further reasons for finding passwords alone insufficient for security, but at least these are strong, and yet potentially memorable, passwords.)