I think many software vendors are at it. Its just now some are starting to be up front about it.
Look at how many want to scan your http traffic for malware protection when file scanning is good enough.
Also nod32 throw a big red alert in their new v9 beta product if phishing protection is disabled.