Yeah but that should be okay as long as he's getting it from legitimate places (rarbg, official fitgirl site, cs.rin.ru, rutracker etc).
I've not had an AV for like 10+ years, had defender disabled with GPO as soon as I installed W10 and had no issues.
The best AV is your brain. Obviously if you download GTA_6
_(Brazil)_by_xP3tYa1337x.pdf.html with an embedded .hta directly from an IP address in Kamchatka and you have IE installed then yeah maybe you need to give things a manual scan pass with defender or malwarebytes (or just toss it in a VM) once in a while but otherwise you're golden.
Even most vulns today labeled 0day are either unexploitable or require the user to be a dumb motherfucker.