Because they have identifiable owners who might wish to travel to Europe and not risk someone deciding to make an example of them.
the idea of the owners of a small, regional US news website being arrested while traveling in Europe because that site does not have a GDPR compliant cookie policy seems utterly detached from reality
I would be more worried about being struck by a meteorite than such a thing
You're making the point even stronger for US companies to just block EU traffic entirely. If you have no EU customers, the mere act of letting EU visitors on your site might cause an EU country to "make an example" of you for incorrect data handling, but the alternative of just blocking all traffic would let you travel to the EU without issues.