Significant engineering time will need to be spent ironing out important things that just work with REST (like caching).
The best analogy I have for what working with GraphQL on the backend is like is the “If you give a mouse a cookie” story [1].
You try to set up an API but end up being asked to implement three different caching layers, using the data loader pattern to batch requests to the DB to improve performance, discovering that custom error handling code is needed to get non 200 status codes back from your API, using persisted queries now that your frontend is asking for a lot of data in the body of the request which is taking up too much bandwidth, etc…
The code as you can imagine after doing all this is very hard to follow, even without doing any of the optimizations I listed above there are things like reference resolvers that make tracking down bugs or just finding where the data is being collected from a nightmare.
[1]: https://en.m.wikipedia.org/wiki/If_You_Give_a_Mouse_a_Cookie