It's not speculation. Tell me what IOMMU group the ME belongs to. Protip: none, because the entire system need not even be aware that it exists. The IOMMU is set up by the CPU, and the CPU cannot see the ME. And no, the Management Engine Interface is not the ME itself, so isolating it (which is entirely possible) does not provide any protection from the ME.
Re: Wrong