Windows updates, Anti-virus updates for Air gapped hosts

If people are using their own usb drives on these PCs it certainly is an issue.

I would set them up on an isolated LAN along with a WSUS server and whatever software you antivirus provides for distributing patches. The new server could either have a second connection to the internet, or stay isolated and have you manually transfer updates to it on a regular basis to distribute to the rest.