You don't have to prevent it from accessing the internet in general to route all requests to a specific company's servers to a fake endpoint that never sends the data to the company and replies with whatever response you want it to get.
The firewall would come with the third party open source software being used to run the model and it would have a list of what to block based on observing what that model tries to do that none of the users actually wants it to.