Installing a kext is a password prompt away, I believe, so all that's needed technically seems to be "install something not reviewed by Apple, fill in a genuine OS password prompt when asked, and run it" which strikes me as a very common scenario.
Then the extension needs to be allowed in System Preferences > Security (this step has been required on Intel Macs too)
/s, though not entirely, moving more stuff to unprivileged contexts would be nice
But yes, there was a time when editing even /etc/sudoers required disabling SIP. That time is long gone.