It's all about compensating controls.
It just not as simple as commenters on this thread wish!
Yes you can go back and forth and argue the toss, but it pushes up the cost of the sale and forces your customer to navigate a significant amount of bureaucracy to get a contract agreed. Or you could just run AV like they asked you to...
It did involve a lot of documentation of inter-machine security controls, network access restriction and a penetration test by an offensive security company starting with a machine inside the network, but it can be done! Also in my opinion it gives you a more genuinely secure environment.
If for instance they're remoting into a restricted VM all day, that's a different set of tradeoffs many might not be happy with.
The romans used to make the architects stand under the arches they built, to enforce the idea of consequences for bad work.
Corporate IT is always going to lean towards the "safe" compliance option.