That's incorrect. That is the attempted naive reach of the EU in action. The correct formulation is: the EU would like for GDPR to apply to all EU citizen data globally.
US sites/services with no business reach into the EU, do not need to comply with EU privacy laws. 99% of businesses around the world (most small businesses), those outside of the EU, will entirely disregard GDPR - because they have no business dealings with the EU.
The EU has no jurisdiction over the US economy or its laws. That will remain the case. The EU also doesn't control China, or India, or Japan, or Brazil, or South Africa.
A simple example for illustration: I can establish a new US service that is ad based (with eg 100% of revenue being derived from the US market), I can keep all of my infrastructure & business operations outside of the EU, I can take on EU users at will, and I can do anything I want to - in compliance with US law - with their information without concern for GDPR: because the EU does not lord over the US, their laws do not rule the US. This is legally how GDPR actually works, despite the amusing propaganda campaign to pretend GDPR requires global compliance.