You might be able to use something like distrobox instead of a full VM. That would at least put it in a container that you could either run from an encrypted partition or something.
Different users would be the “simple” way you’d normally do something like this under Linux. But if your regular users have sudo access, you can’t really lock anything down.







Information pollution.
Saying “AI pollution” would be like saying “microplastics pollution” – we generally refer to the thing being polluted, not the pollutant.