Kagi is a US company. GDPR is not a US law.
(Do you regularly check to make sure you're obeying laws in countries you don't ever intend to visit? No? Then why should Kagi?)
I suppose a serious breach of regulations, and if Kagi decided to ignore fines, apart from a bad reputation, could ultimately lead to things like judicial decisions of blocking access to the website or blocking payments for EU customers.
The scope of GDPR is clearly including businesses operating from the US, but has any company registered only in the US ever been fined by EU?
This means they're exposed to GDPR not only indirectly by serving EU citizens but also directly by operating within the EU.