The linked article isn't describing a form of input sanitization, it's a complete separation between trusted and untrusted contexts. The trusted model has no access to untrusted input, and the untrusted model has no access to tools.
Simon Willison has a good explainer on CaMeL: https://simonwillison.net/2025/Apr/11/camel/