^^ similar concern>>> happening for ten years now: the subversion of the os via hardware
Yeah that Intel ME ghost has been lingering for a few years now. You want a system with Intel ME crippled or disabled. If you are comfortable with a ROM flasher and doing some micro-soldering, you can use ME cleaner:
https://github.com/corna/me_cleanerMy money is on hardware vendors who claim to burn a fuse on the processor that powers ME, ie. system76 / Purism. Dell had a system listed with ME disabled but I wouldn't trust it.
Plenty of rumors about low-level USB exploits as well.