At INRIA (a French computer science research institute), AV became mandatory on Macs last year.
A colleague of mine got hit recently by a crypto-miner on their Mac. I don't know if they had an AV, and if so, if the AV would have caught the miner. This was detected by the IT department by monitoring suspicious traffic.
I don't use a macOS so I can't really say. I see AVs as another piece of proprietary software that you have to trust, and that takes significant resources without knowing how useful they are.
On Windows, I would probably use the one from Microsoft, since it's free and since I would already "trust" Microsoft by using their OS and I would somewhat bet that it is in their interest to keep their OS safe. I can't be sure tough: why is it not integrated by default (or is it?)? To allow competition? Then is Microsoft making their antivirus less efficient so the competition is still relevant? And maybe AV is not really Microsoft's main business so their antivirus may be lacking?
On the other side, I would bet it is in the interest of other AVs to always nag you and make you feel they are present and useful more than being actually efficient for other things than high detection rates in benchmarks.
They are irritating and advertise themselves in people's mail signatures, sometimes outright lying: "this email as no viruses" - That you can't be sure, and the mail could have got a virus in its way between the sender and the recipient.
By design, AVs can't really detect new viruses and I would not feel really more confident with an AV than without because of that. AVs didn't catch ransomwares when they first appeared after all.
I don't use any antivirus. My approach to security is:
- Using only free software, as much as possible (I know, I would need to audit everything I use for this to be perfect, but I can't possibly do that).
- that is preferably installed from the OS vendor, which I have no choice to trust anyway.
- usage of an ad blocker with more filters than the default
- be careful where clicking links
- instant backups in a self hosted cloud for important things, and automatic daily snapshots of this cloud somewhere else
- and I also happen to never be browsing sketchy websites.
- all this is true on my phone as well.
One could add usage of Google safe browsing or something related for phishing. And also blocking Javascript or third party Javascript by default when browsing, which I did at some point in my life but which is not convenient for most people.
Would I recommend AV for somebody who uses an OS that is more targeted by viruses than mine, and is likely to fell in a trap (the kind of trap an AV would catch anyway)? Probably Windows Defender on Windows, for Macs I really don't know. If there is an AV provided by Apple or by some other company you trust, I guess I would go for it rather than having nothing.
You can always get viruses from the network that will silently exploit an unfixed security breach on any system, and that may remain undetected so at least, I would tell them to be careful, to keep their system updated and to make backups regularly (ideally, backups should be automatic to some extent), since AVs can't guarantee that no virus will make it.
I would make sure that they are not too confident in the AV, too.