They're called proprietary video drivers, and yes, they pass unknown commands, without user authorization (think DRM) to PCI(e) devices (video cards) all the time.
If you're running highly privileged binary blob drivers, is ME really the attack vector you should be worried about?