(go ahead, click it)
Depending on platform, this is even more fun with command lines with commands like: `open familyphotos.zip`
But the point is, unless you are technically skilled, you probably can't tell whether you're about to go to a trusted file or download something random.
Depending on the context you would probably expect to be taken to a local file on the disk, you would never think this would download something new unless you were already in a context to do so.
Note that Google is also doing this for .mov. Both are file formats which can execute code (zip and mov both have exploits).
These TLDs should at least be removed from the PSL.
Edit: Here's a PoC screenshot: https://twitter.com/mholt6/status/1657133439546695680