Memory Safety Becomes Policy
A survey of 850 engineering leaders at technology companies with more than 1,000 employees found that 31% of new systems-level projects are now started in Rust rather than C or C++. Two years ago, that figure was 12%. The acceleration reflects both maturation of the Rust toolchain and increasing regulatory and internal policy pressure to adopt memory-safe programming languages.
Government Push
The US Cybersecurity and Infrastructure Security Agency's 2025 guidance explicitly urging adoption of memory-safe languages for new systems software has elevated the conversation from engineering preference to security policy. Microsoft, Google, and Amazon have published internal mandates requiring Rust or equivalent memory-safe languages for security-sensitive code in new projects.
Real-World Deployments
Google rewrote significant portions of Android's Bluetooth stack in Rust, reporting a 52% reduction in memory safety vulnerabilities. Microsoft rewrote Windows kernel components in Rust for Windows 12's experimental branch. The Linux kernel's Rust integration now covers multiple driver subsystems. These high-profile deployments create organizational templates for enterprise adoption.
Developer Onboarding Time Drops
Rust's historically steep learning curve has shortened materially. Tooling improvements in the Rust 2024 and 2025 editions, combined with AI-powered code completion trained on Rust idioms, have reduced time-to-productivity for new Rust developers. Survey respondents reported new developers reaching useful productivity in 6-8 weeks, versus 3-4 months historically.
What This Means for the Market
For every new systems project started in Rust, that's a project where future memory safety CVEs — the class of vulnerability responsible for approximately 70% of Microsoft's security patches — are architecturally prevented rather than patched after discovery.