The current trend in security seems to be heavy sandboxing, period. And anything that gets in the way of said sandboxing, however benign, is considered insecure, full stop...
The code we're talking about isn't benign. It's incredibly complicated and has one of the worst track records in all of software security.
Wait, are you talking about browsers or AV now :D
AV. Browsers, too, but browsers at least have a good excuse.
It's the principle of least privilege. Give apps (and websites, and even parts of core services/infrastructure and kernel code) only what they absolutely need. Every syscall you can say shouldn't ever be called is one less avenue for attack. Benign isn't good enough. You need to actively justify every privilege, and leaving a few open for "benign" reasons is bad practice.