Of course you might not care, if you believe that the EU has no way of forcing you to pay a fine and if you are certain that you are never going to do any business in the EU. But in such case you might as well provide access to your models for EU IPs too. It makes no difference.
The model access makes no difference.
"Personal data" and "data processing" are (deliberately) drawn very broadly:
"""Personal data — Personal data is any information that relates to an individual who can be directly or indirectly identified. Names and email addresses are obviously personal data. Location information, ethnicity, gender, biometric data, religious beliefs, web cookies, and political opinions can also be personal data. Pseudonymous data can also fall under the definition if it’s relatively easy to ID someone from it.
Data processing — Any action performed on data, whether automated or manual. The examples cited in the text include collecting, recording, organizing, structuring, storing, using, erasing… so basically anything."""
And, unlike the arguments about copyright in big AI models trained on the internet (is it 'fair use'? Don't ask me, IANAL!), the requirement for explicit and informed consent is something a general crawl will very clearly fail:
"""Purpose limitation — You must process data for the legitimate purposes specified explicitly to the data subject when you collected it."""
Furthermore, we don't know enough about how the models store knowledge/beliefs to be able to make any claim about accuracy:
"""Accuracy — You must keep personal data accurate and up to date."""
And as for confidentiality… for downloadable models, that's "by obscurity" only, due to the exact same research needed to resolve the previous point about accuracy, and even for secret models like GPT-4, nobody's really sure how to actually guarantee it won't leak info with the right prompt, and there's even some suggestion that this is actually impossible with current approaches because nothing is really deleted by RLHF:
"""Integrity and confidentiality — Processing must be done in such a way as to ensure appropriate security, integrity, and confidentiality (e.g. by using encryption)."""
In the case of #1, they probably do not have an agreement with the "data controller" in the case of scraping, which means #2 is a violation of GDPR.
IANAL.