Did a bit more looking into this and it seems to be the case. The issue is with organisations that have historically captured info about EU citizens which even if they stopped access to new EU users, still makes them need to comply with GDPR. So preventing access might also need to be supported by removing any EU user data from your system. Discussed in detail below.
https://www.econsultancy.com/blog/70065-gdpr-which-websites-...