American companies "complying" with is only required insofar as the EU authorities can do anything about it - and that's the same dynamic that exists across all geo boundaries on the internet, that's not specifically American - see China and its great firewall. If an American company is taking steps to be in compliance with GDPR, it's because there is benefit in doing so.
WRT GDPR, I'd ask a clarification before continuing - you said "operating within the EU" - what does that mean? If I deploy a website, from America, onto American servers, and you can reach them from within the EU, am I "operating within the EU"? I'm not trying to be coy by asking this, I actually don't know the extent to which I agree or disagree with you.