Ugh, yep. I totally forgot about how many machines come with entire parallel communication systems. The Intel Management Engine, for example, is
horrific. It's a machine-compromising threat built into the CPU and (as far as I know) totally unremovable. I haven't heard about any kind of compromise, but it's far from impossible. Well-meant, sure (why make two production runs at higher expense), but that's not very comforting. We already know the US government intercepts some machines in transit; silently enabling and owning the IME would be an elegant way to beat a physical inspection on delivery. It's only reasonable to assume China and similar players do the same.
(If the IME is disabled, will the CPU still complain if you physically destroy the thing? Does anyone know?)
There's also the rather nasty proof-of-concept attack where air-gapped machines output audio data at ultrasonic frequencies to beat the gap. Sure, it takes initial compromise to activate, but that's a plausible risk for someone running nation-state defense.
Sneakernet continues to be a solid policy. I don't remember who, but some notable security researcher talking about Lulzsec summarized the issue with "If I were crossing a government, my opsec would be a stolen library card in a city I don't live in."