The standalone microcontroller in your physical keyboard can run arbitrary code, and it's been able to since we've invented keyboards attached to the computer via a port. What's there to stop the manufacturer (or a sophisticated attacker) from:
- recording your keystrokes in non-volatile memory, to be extracted later?
- exfiltrating them in real-time via Bluetooth (yay for wireless peripherals), WiFi, LoRa?
- asking the OS to install a driver, which (even if approved/signed) could have exploitable security holes?
The main hurdles are scale and sophistication, which, with an all-software "keyboard", were no longer an issue.