You can put the untrusted VMs in the cloud, to get better isolation between them and more important stuff. This, e.g., is a way of preventing two colluding VMs from communicating.
That's a very interesting take, you can run local network for trusted qubes and put more risky/untrusted qubes on "cloud" VMs, that way you strongly mitigate colluding VMs (same-machine & same-network) and VM excursion attacks on your hypervisors & physical machines.