That's a rather strong way of putting it, but yes, you should assume that every device you use can be penetrated by a sufficiently advanced and motivated actor. You should also be comfortable with the fact that state level actors have been recording information so that they can reach into your past should you ever become a problem with them. In that mindset, you have to create a security environment such that the truly advanced actors aren't motivated enough to bother with you. At the same time, don't leave your front door wide open so that any teenager can walk in and steal your TV.
I'm personally not worried about the 5eyes (but anti-gov activists should be). I'm worried about the smart kid who can use metasploit to take the banking info off my laptop in the middle of the night without me knowing it. A Purism laptop doesn't protect me from the smart teenager any more than an HP does. Full disk encryption and a Yubikey probably does, along with a decent firewall. Using cloud services where I encrypt my data before uploading is better than one where I transmit unencrypted (or where the cloud service controls the key).
A company willing to drop several thousand dollars on a Talos II might be worried about corporate espionage, so they might be willing to pay for a verifiable bios.
The NSA has to worry about thousands of hackers from dozens of countries around the world, so they are willing to pay for custom silicon.
Of course, you also need to consider physical security, which is like this: https://xkcd.com/538/