AU plugins work, the AU framework itself spins up a separate process to host the translated Intel plugin.

That's actually what's going on, it turned out -- I'm using the AU version of the plugin, Activity Monitor lists an Intel process when I add it to a track.

Not sure this will be of any help to my projects once Rosetta 2 gets sunsetted...

Yes, that's how you do it. I have written a VST plugin host for Pure Data and SuperCollider and it supports sandboxing/bridging. It's not rocket science. I'm not sure why Ableton never bothered to implement this.