The EU AI Act is the first comprehensive attempt to regulate artificial intelligence by statute, and it is already functioning as a template. Draft bills in several countries reproduce its structure closely: a tiered classification by risk, obligations that scale with that tier, and a supervisory authority with the power to fine.
Copying the structure is the easy part. What determines whether such a law works is the enforcement capacity behind it, and that is where most adaptations run into trouble.
What the risk tiers get right
Regulating by application rather than by technology is the Act's most transferable idea. It avoids the trap of writing rules against a specific architecture that will be obsolete before the law takes effect, and it puts the obligations where the harm actually occurs — in hiring, credit scoring, policing, and border control.
Where it is straining
The general-purpose model provisions were retrofitted late and show it. Compliance costs fall hardest on small developers, and several of the transparency obligations are difficult to verify in practice. The supervisory bodies are understaffed relative to the mandate.
The transferable lesson
A law without an enforcement budget is a signalling exercise. Countries adapting this framework would do better to regulate fewer applications properly than to legislate broadly and enforce nothing.