I do know some extremely reputable researchers, people with no connection at all to the supposed events, who have very forceful arguments for how the (scant) evidence Dragos produced didn't establish anything about the existence of anything like BadBIOS.
You're probably not going to get closure on this story.
Literally nothing. If something jumped an AirGap then a USBdrive, or CDrom/DVDrom, etc. was infected. In which case the system wasn't Air Gapped, it was part of a sneaker net.
Most commonly we refer to sneaker nets as Airgaps, when often their just as vulnerable as a normal network. Dirty USB sticks are an old as the hills hack at this point.
Hence 'airgapped" (not connected to the network) computers could still export private information to a botnet operator.
'Airgapped' computers without infected BIOSes could not leak information. Sneakernet computers with bad BIOSes could.
Unless you can pull off a remote code execution via microphone input, or speaker feed back. Its unlikely an air-gapped computer will be infected.
If I've got drivers running on two computers that only are in the same room, and they both have speakers and microphones, then yes, I may be able to pull this off. If one of them is connected to the outside world and the other isn't, I may be able to connect from the outside world to the unconnected computer using this acoustic method.
None of this helps me get the infection on the unconnected computer, though. For that, there has to be something else - sneakernet USBs, for example, as you mentioned.
More seriously, the "virus that jumps airgaps" was a sensationalist headline from the get-go. I just was trying to explain where the claim originated.
The main issue always was Dragos' inability to isolate any suspicious artifacts besides "I can't burn CDs!".
Basically his story required there to not only be firmware malware that could infect a wide variety of devices, but for said malware to somehow exist in a part of the firmware/BIOS chip which couldn't be dumped for examination. Even if such a thing existed he still could have tapped a logic analyzer onto a USB cable, plugged in some fresh hardware, and captured what the malware did.