The many rules of the EU stifle speed and change the math for releasing something especially in a big company that has a variety of requirements built up over time to reduce litigation risk or being on the wrong side of one of the overreaching government officials there.
The process should be the reverse of that. Don't collect data unless you have been through the process of checking that it has a legal basis.
I bet the people at Peloton thought that too until they made that treadmill[1]. I know you meant your critique to be absurd, but it turns out creating a child eating machine by accident is entirely possible. I also bet Peloton product development now includes a process to review child-eatingness despite that not being their primary market, just the usual twice burnt reflex.
Accidentally logging the PII can easily happen for a single engineer. I managed to do it on an product that was privacy-focused & the error slipped through review. The odds of such inadvertent errors rise linearly with the number of products and engineers, and the fines are probably superlinear with the size of an offending organization. If your 3-person consultancy chomps on a GDPR baby or 2, no one will ever know about it, but if Google does it, it's going to be news headlines an millions in fines.
Legal basis is ever shifting based on the regional locale. As n+1 requirements pop up, it's only natural to release things like GenChess in the place that requires the least friction, especially when it is not a revenue generating event.
(I am a Googler, but not on this team, or familiar with their launch policies)
Much, much wiser to assume "there be dragons" and only engage once qualified legal counsel has helped you understand what compliance means to you.
And along these lines... The second least wise thing to do in this scenario is listen to randos in a forum like this tell you, "but all you have to do to comply is..."
To devise such a way to comply, they definitely need a large and expensive legal department.
The privacy abusers are much like trolls on the internet who, upon seeing a code of conduct (previously known as "rules") consisting of only "don't be a dick", will spawn endless arguments about what a "dick" is and how it is or is not inappropriate word, what does it really mean to be one, or, indeed, to be, question the use of the indefinite article, and complain about "don't" being too assertive and arrogant.
There are non-malicious explanations for the same pattern of behavior at large organizations - the motivation (malice or not-malice) that seems correct is a Rorschach test.
If I accidentally log IP addresses for EU users that opted out on some throw-away experimental page on my site, Brussels would never find out. If Google does it, it not only has to report the incident, but will most likely be fined. In order to avoid this outcome, they have internal review processes which makes ot "complicated and insurmountable", because how do you justify investing many hours of dozens of lawyers and technical reviewers time for a frivolous, niche AI demo?
If opting out is a possibility, then it's not essential data. If it's not essential data, what legitimate reason would you have to collect it in the first place?
Accidentally logging data that's essential but was supposed to be ephemeral would turn it "not-ephemeral" and make it possible to cross-reference with other information in privacy-defeating ways. As I said, it was a privacy-focused product, and using data that is meant for one thing (e.g. abuse detection and prevention) for some other out-of-spec use - even accidentally - is a big no-no.
Those that have to follow those laws need to care about the mess.
Doesn't the EU also have an 'AI Act' that imposes additional rules, even when you're not tracking anyone?
And a lot of employers have legal teams who are extremely risk-averse, so even if it's obvious to you and me that rules about "deepfakes" don't apply to a tool for generating pictures of chess pieces made of cheese, doesn't mean legal will sign it off.
Sadly, GDPR is not a black-and-white (pun intended with the chess project) checklist with black-and-white checklist items.