We have existing paradigms for this.
Additionally, installers are signed with certificates on Windows.
All of these are strictly more trustworthy than curl | bashing.
With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.
REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.