The tools developers use shape the software they ship. Over the past few years, a handful of languages and tools have moved from enthusiast projects to mainstream choices: Rust for systems code where safety matters, Go for cloud services, Kotlin for Android and modern JVM work, and AI coding assistants that sit in the editor or terminal and take on real engineering tasks.
This is not a story about fashionable syntax. Each of these shifts responds to a concrete business problem: security flaws that keep recurring, services that need to scale cheaply, mobile apps that must be maintained for years, and engineering teams that cannot hire fast enough. For technology leaders, the useful question is not which tool is best, but which problem you are trying to solve.
Rust: security through memory safety
A large share of serious security vulnerabilities in software written in C and C++ comes from memory-safety bugs such as buffer overflows and use-after-free errors. Rust prevents most of these at compile time through its ownership model, without the performance cost of a garbage collector.
The evidence from large codebases is persuasive. Google reported in 2024 that memory-safety issues had fallen from 76 percent of Android vulnerabilities in 2019 to 24 percent in 2024, largely because new code was being written in memory-safe languages such as Rust and Kotlin rather than rewriting old code. Rust has been accepted into the Linux kernel, and US agencies including CISA and the NSA have urged software makers to publish roadmaps for moving to memory-safe languages.
The trade-off is a steeper learning curve. Teams typically need several months to become productive, and the compiler is strict by design. Rust earns its place in components that parse untrusted input, handle network traffic, or run close to the operating system, rather than as a blanket replacement for everything.
Go: simple, scalable cloud services
Go was designed at Google for building networked services that are easy to read, fast to compile and simple to deploy as a single binary. Much of the cloud-native ecosystem is written in it, including Kubernetes, Docker and Terraform, which is a strong signal of its fitness for infrastructure and backend work.
Go’s strengths are predictability and onboarding speed. A developer from another language can usually read and contribute to a Go codebase within weeks, and its built-in concurrency model suits services that handle many simultaneous requests. It is memory-safe for most practical purposes, although it is less expressive than Rust and does not offer the same compile-time guarantees around concurrency.
Kotlin: the default for modern Android
Google announced in 2019 that Android development would be “Kotlin-first,” and new Android libraries and documentation now assume it. Kotlin interoperates fully with Java, so teams can adopt it file by file inside an existing Java codebase, which lowers migration risk. Its null-safety features eliminate a common class of crashes, and it is increasingly used for server-side JVM work and for sharing business logic across Android and iOS.
AI coding assistants: from autocomplete to agents
The biggest change in daily development work comes from AI assistants. The first generation offered line-by-line autocomplete. Current tools, such as GitHub Copilot, Cursor and Anthropic’s Claude Code, which runs in the terminal and integrates with popular editors, can read a codebase, plan changes across multiple files, run tests and iterate on failures.
Used well, they compress routine work: boilerplate, test scaffolding, migrations, documentation, and explaining unfamiliar code. The results are not automatic, however. A randomized study by METR published in July 2025 found that experienced open-source developers working on their own mature projects were about 19 percent slower when using AI tools, even though they believed the tools had sped them up. The lesson is that gains depend on the task, the codebase and how the team uses the tools, so they should be measured rather than assumed.
AI assistants also raise governance questions. Code may be sent to external services, generated code can include insecure patterns or unvetted dependencies, and agents that run commands need clear limits on what they may touch. Our AI consulting and agentic AI solutions include setting up these guardrails.
How to adopt new tools without disrupting delivery
Changing languages or tooling has real costs in training, hiring and maintenance. A structured approach keeps those costs in proportion to the benefit.
- Start from the problem. Recurring memory-safety bugs point to Rust. Slow, complex backend services point to Go. A Java-based Android app points to Kotlin. Repetitive engineering work points to AI assistants.
- Pilot on a bounded component. Choose a new service, a parser or a single module rather than a rewrite. New code is where most of the benefit lies.
- Measure before and after. Track defect rates, security findings, cycle time and on-call incidents so the decision rests on data.
- Set AI usage rules. Decide which assistants are approved, what code and data may be shared with them, and require the same review and testing for AI-generated code as for human code.
- Invest in people. Budget for training time and pair experienced engineers with those learning, especially for Rust.
- Plan for the long term. Consider the hiring market and who will maintain the code in five years before committing a critical system to a new language.
The trade-off to keep in view is fragmentation. Every additional language adds build tooling, security scanning and hiring requirements. Most organizations are better served by a small, deliberate set of languages than by adopting each new option as it becomes popular. For more on how engineering roles are changing, see how developers are powering the next tech revolution and the rise of the DevOps engineer.
Frequently asked questions
Should we rewrite our existing C or C++ code in Rust?
Usually not all at once. Google’s Android experience suggests the biggest gains come from writing new code in a memory-safe language, because older code has already had many of its bugs found and fixed. Rewrite selectively, starting with components that handle untrusted input.
Are AI coding assistants safe to use on proprietary code?
They can be, with the right configuration. Use business or enterprise plans that exclude your code from model training, restrict which repositories the tools can access, and review generated code with the same security checks you apply to any contribution.
Is Go or Rust better for backend services?
Go is typically faster to adopt and well suited to most web services and APIs. Rust is a better fit where performance, low latency or strict safety guarantees justify the extra learning effort. Many organizations use both for different components.
Modernize your development practice
Delana Technologies helps teams choose and adopt modern languages, secure their software supply chain, and roll out AI coding assistants with sensible guardrails. To discuss your engineering roadmap, call 239.414.5126 or contact us.
Sources: Google Online Security Blog, “Eliminating Memory Safety Vulnerabilities at the Source” (September 2024); CISA and partner agencies, “The Case for Memory Safe Roadmaps” (December 2023); Android Developers, Kotlin-first announcement (Google I/O 2019); METR, “Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity” (July 2025); Anthropic Claude Code documentation.
