Perhaps he uses the Mac Studio for more important work?
As you put it, it really is a desire for maximum security at play here.
"Just allowing kexts to be loaded" sure, it wont. But "just allowing kexts to be loaded" makes no sense as an action, unless you also actually intend to and do load at least one kext.
In which case, it absolutely increases the attack surface.
Booting that computer from an external drive with third party kexts would also increase the attack surface, right?