I’m collaborating on an attempt to shift the responsibility for XSS from the developers and towards the browser. The current stage focuses on getting the use case "insert HTML but without any scripts" right.
There’s a public specification and prototype implementations in Firefox and Chrome. You can play with it here https://sanitizer-api.dev/
We think that we’ve made the best of many different tradeoffs, but we’re also keen to hear wide feedback.