US Government systems typically use client certificates as a component of access control in the form of the Common Access Card[1]. Not that that's a business, or even a success from the point of view of the users, but it's one of the largest deployments of client side certs out there.
[1]: http://en.m.wikipedia.org/wiki/Common_Access_Card