Earlier quoted context omitted.
You can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.
The GDPR relies on international treaties to make the location of the business irrelevant. Any company processing data of EU citizens must comply IIRC.
But I can't find anything about how they'd make it enforceable in other jurisdictions (as opposed to enforcing the judgements by e.g. fining EU subsidiaries and the like).
Article 50 does say the Commission should take "appropriate steps" to ensure international "cooperation mechanisms", and its clear under e.g article 44 onwards that carrying out a transfer to a jurisdiction where the data would be subject to inadequate controls would be a violation of the directive, so you may very well be right.