Two issues that have been pit falls on windows. The user puts too much trust in said AV system, not understanding its limits and capabilities, subsequently stopping doing his own due diligence in the vast depths of the net.
Also, historically AV programs were used to breach systems. They usually enjoy a high level of access, but the team behind these programs isn't magically bigger than any other piece of software. As such a target for attackers, who study the AV software to circumvent it and as a result, may stumble one ways to use it as an attack vector.
You can have false positives and false negatives, which can cause even more problems and train people to ignore whatever the antivirus says.
The antivirus can cause security problems as well, things like man in the middle proxies to scan HTTPS traffic, but they "forget" to check the certificates, which handily disables the entire point of HTTPS.
Basically it's makes security worse, and consumes resources that would be better used elsewhere, like say with a whitelist.
e.g. historically anti-virus engines have had bugs where e.g. when they search inside of a .zip file; their .zip parser was susceptible to a buffer overflow that would have allowed a malicious file when scanned to run arbitrary code.
e.g. some anti-virus software has a daemon that runs on localhost with an exposed port. This port receives RPCs. websites in your browser have been able to make requests to the anti-virus daemon.