Hi,
As per my understanding I don't see any further scope for automation.
Already you are doing what you can do.
Few points I would like to share:
I believe it's not possible that clients will automatically report to the appropriate group in the SEP Manager without AD synchronization.
You will have to export the appropriate package which you are already doing.
I would suggest let the clients come into the default group and move them appropriately instead of exporting package for each group.In this case you would required only one package. Again for this activity some manual intervention is required.
I am not much convince with the reason that due to future SEP update you are not willing to add it in the base image. In the future you can simply do auto upgrade to upgrade existing SEP clients with the help of SEPM. No need to update image itself.
http://www.symantec.com/docs/TECH96789