So first of all - just because the end-user wants Apple to check for actively malicious programs doesn't mean they assent to all forms of control. Secondly, even on the matter of software deemed malicious by Apple, I think it's questionable how reasonable it is for Apple to entirely remove the end-user from the decision making process.
Even on really weakly policed platforms like windows, people still tend to leave virus scanners enabled; and on android similarly most people don't choose to expose themselves to unnecessary risk by sidestepping its store - at least as far as I know. Users regularly do really stupid things, so some level of external control is perhaps not unreasonable, but how much, and for what? And should Apple even get to be involved in that decision?