Take a step back, and look at history. It should be unsurprising that the problem was encountered, studied[0] and solved, decades ago.
During the Viet Nam conflict, the Air Force needed to plan missions with multiple levels of classified data. This couldn't be done with the systems of that era. This resulted in research and development of multi-level security, the Bell-LaPadula model[2], and capability based security[1].
Conceptually, it's elegant, and requires almost no changes in user behavior while solving entire classes of problems with minimal code changes. It's a matter of changing the default from all access to no access, all the way down to the kernel.
Life without it, is like trying to run a modern electrical grid without any circuit breakers, anywhere, ever.
Getting rid of virus scanners alone should be worth the platform switching costs, at least in terms of performance for most users.
[0] https://csrc.nist.rip/publications/history/ande72.pdf
[1] https://en.wikipedia.org/wiki/Capability-based_security
[2] https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model