I think what you're missing is that if you don't use AMT, all of the other boot security built into the system can be bypassed. Presumably this is important because if you don't want to use AMT you probably would assume that it's secure by default, but it turns out it's not.