This is not particularly new. The Baseboard Management Controller has had a similar capability for ages, with less security. This has been mitigated to some extent by the fact that everyone KNOWS if there is a BMC because they actually ORDER it; it's usually only installed on servers and other enterprise hardware.
The Intel implementation of the IME appears (so far) to be fairly secure, although it is obviously only a matter of time before someone figures out a way to compromise it. Since a fair bit of it is baked into the silicon, it will probably require someone to actually decap a chip to see what's going on. Unfortunately, that also means that once it is compromised, it likely can't be fixed, since what little we know indicates it's on ROM, not EPROM or FLASH.