Forget all the stuff out there that says the GDPR protects EU citizens. This is a question of jurisdiction and enforcement. Say I run a blog under a business registered in the US funded by advertisers in the US. A EU citizen that comments on posts issues a GDPR request that I ignore. Their government fines me. I tell them to get bent, I am out of their jurisdiction. What can they do at that point?
Your advertisers who most likely sell stuff to EU people will become party to your noncompliance, and will be unable to use the data you sell them, and may cut ties for liability reasons.
Also some jurisdictions in the EU reserve the right to submit incassos directly to the SWIFT system, but that’s mostly used for eg. speeding tickets.
For example if you come here to my country from the US with your car and get a speeding ticket that you refuse to pay, my government will just take it out of your US bank account unilaterally. GDPR fines are criminal fines just as speeding tickets are.
Realistically though, if you don’t have massive wealth to bribe people in the US, the US authority will just enforce the fine on you.