const escaped = escapeHTMLPolicy.createHTML('<img src=x onerror=alert(1)>'); console.log(escaped instanceof TrustedHTML); // true el.innerHTML = escaped; // '<img src=x onerror=alert(1)>'