Even if that's true right this minute, an unauditable (:/) bit of hardware controlled by Microsoft (!) that can be force-updated by them (!!!) means this can change at any moment.
I liked TPM with my own keys. This just seems a bit 'extra' in all the wrong ways.
Firmware updates can't add network hardware where none currently exists. The block diagrams for Pluton don't give it any mechanism to communicate with the network directly.
Anything evil will likely be brokered through the OS. While this is good in that it's not a persistent backdoor like Intel ME, there's still Microsoft skulduggery to worry about.
Good news! Pluton is not internet enabled and can't monitor your software.