Seems to me the answer is to use physical separation instead of virtual machines. Just get the AI a cheap laptop or phone with a cellular connection (so it's not on the same network as your other potentially vulnerable machines).
So it can hack the cellular network instead?
So it can hack the cellular network instead?