I haven’t seen your stance on VMs, but a lighter approach might be confining the software to an AppArmor profile or such. The kernel will enforce the restrictions on what it can and can’t do.
It won’t have the overhead of virtual machines, and you can keep using a single video card, but setting this up is quite tedious, though.