Earlier quoted context omitted.
Then XSS attacks would insert before =) What we need is literal separation of control statements (eg, ) from content such that neither can be easily misinterpreted, but that would be a significant departure from existing design.
That shouldn't work for the same reason that you can't escape a bound SQL query parameter in a pre-parsed query.
And with modern type systems, these types might even be phantom types incurring no runtime overhead. Athough things like the differences between "safe for passing to a browser" and "safe for passing to my SQL-server" might compliate the architecture.