I posted it below already, but anyway as far as I personally understand to provision AMT you need it actually enabled in BIOS / EFI and it's in fact usually disabled by default.
Am I missing something?
Privileged users usually have BIOS access. BIOS's are often designed to be configurable/flashable with vendor-specific tools that your run on top of your OS.
AMT exploits are a side channel attack. AMT has it's own processor, loads from it's own ROM separate from the BIOS and has it's own network stack but has full access to the system at a hardware level. AMT System Management Mode hooks in to the CPU at ring level -2, below the OS and is remotely exploitable.