https://support.apple.com/en-us/HT208465
See the "EFI" section.
Exploiting the ME is possible even without AMT but it definitely raises the bar in the sophistication of the attack.
The me_cleaner tool might do a good job in disabling the ME in most cases but since it's doing it by removing components from the ME FW it probably doesn't work with every OEM implementation.
I don't think they've ever used the Intel NIC hardware either, wired or wireless.
and you can minimize ME in Sandy and Ivy Bridge, using ME_Cleaner?
edit: according to sounds' comment* in HN (2016), The ME is purportedly placed in "recovery" mode
But very stable, I am looking to flash my X220 soon for what it's worth.
https://libreboot.org/docs/hardware/gm45_remove_me.html
after that it's impossible though.