That's a good point. The unique device ID is baked into the hardware, but it doesn't look like it can be read directly, so it might not even be able to put in logic based on the ID into the firmware anyways.
The software would only disable those features on that specific device, which would be hard coded. Even if you moved the software to another device, it wouldn't work. Even if you had the source code, and modified to work on a different device or all devices, you wouldn't be able to do it unless Apple signed the modified software as well.
This is the technical aspect that I think isn't getting nearly enough attention. While I agree with Cook that this will set a precedence where governments, both the US and others, begin making these requests more frequently, it's not actually creating a master key in this case. Apple would have to be compliant in each individual case to apply this software to another device assuming they code in the specification that it's only applicable to this device.
This still leaves them the ability to remove their ability to do so in the future, by requiring the passcode to update the firmware on both the hardware itself and the secure enclave.