'For the vast, vast majority of its customers, keygen files are going to be malware.'
That's just not true though. They have the ability to detect malware. What they are doing is blindly labeling anything reslembling a keygen as malware , for no valid reason. This also doesn't just apply to Defender.
The problem is that "the hundreds of thousands of malware used to train Defender" include keygen files that do not have any malicious behavior and just generate keys, mixing them together with actually malicious keygens that e.g. try to install some rootkits. It's not a false positive mistake, it's a whole class of intentionally misleading false positives, censoring a type of not-malware that is not wanted by Microsoft but potentially desired by users.
That's just not true though. They have the ability to detect malware. What they are doing is blindly labeling anything reslembling a keygen as malware , for no valid reason. This also doesn't just apply to Defender.