On  the news that the next Linux Kernel will use nftables instead of iptables (http://www.phoronix.com/scan.php?page=news_item&px=MTQ5MDU), I had a look at the existing iptables actions in fail2ban. There are 10 separate configs: https://github.com/fail2ban/fail2ban/tree/master/config/action.d.
I have not seen enough about nftables yet to know how much work it would be to convert to nftables.
nftables also has an iptables compatibility mode, so I don't think there is necessarily a rush to do it, but I wanted to bring it up so that 1) it is on the radar and 2) if there is anyone who knows more about it.

- Y