What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
Sibling comments already gave legal advice, but what I'd ask is: why would you want to? If you are transparent about what tracking you do and don't do stuff that people don't want, all that's left is including some boilerplate text like "you have rights X, Y and Z and you can contact us at our@email" and you're GDPR compliant. To me at least, 95% of GDPR compliance is just acting ethically.
Doing that requires understanding a law with out much case precedent, that is extremely broad and has a whole spectrum of enforcement options.
I completely see why a small org might decide to just geo block. That’s an easy to implement, easy to document & defend attempt at compliance.