Forget all the stuff out there that says the GDPR protects EU citizens. This is a question of jurisdiction and enforcement. Say I run a blog under a business registered in the US funded by advertisers in the US. A EU citizen that comments on posts issues a GDPR request that I ignore. Their government fines me. I tell them to get bent, I am out of their jurisdiction. What can they do at that point?
GDPR applies to American enterprises if they process personal data of EU citizens.
If you serve a website which is accessible to EU citizens, and that site collects personal data or allows users to enter personal data, GDPR most probably applies to you. IANAL.
True, but it’s important to note that personal data means identifiers such as name, date of birth, location, etc. Comments on a blog, by themselves, are not personal data.