I guess I just don't see why it would be any different than current-day iptables.
nftables is made by the same people as iptables, and both are heavily integrated into the kernel (this is what prevented nftables from becoming the defacto linux firewall before; was waiting on kernel integration, I think it first made it in sometime around 3.18 if memory is serving well).
Let's just say after the past few years I'm not brimming with eagerness to give the benefit of the doubt. That said in this case I actually do see the problem the new system is trying to solve, and think it's got a lot of cool stuff to offer.