I don't think this is a very well through out opinion of GDPR. GDPR applies equally to all companies that trade in Europe, not just US companies. So it's difficult to describe it as an attack on US companies.
Additionally GDPR simply enshrines some pretty basic social norms around informed consent and transparency. It doesn't prevent anyone doing anything that's privacy invasive, it just requires that:
1) You tell people what you are doing with their data (in plain English)
2) You get their informed consent and give them the option to opt-out (additionally you can't bundle multiple "purposes" together).
Both of those things seem pretty fair to me, and it certainly a standard that we apply to other aspects of life (with sex being the most obvious example).
So Facebook could train their self-harm detecting AI in the EU, and it can deploy it there. It just needs to ask and get consent from people first, and honour their personal choices.
Equally they could train and deploy their face recognition technology in the EU as well. But again they need to get informed consent, and they can't coerce people by only offering their self-harm technology if they also opt into their face recognition technology (they can't bundle multiple "purposes").
Altogether I think that this is pretty simple and fair, and really technology companies are only suffering because in the past they have collected personal data indiscriminately on the basis that it might be useful some day. And for companies that rely on tricking people into handing over personal data, I don't think the world will suffer without them.