If I understand correctly, you're asking whether the AP firewall rules are applicable to site-to-site VPN traffic?
The firewall rules present under the wireless configuration is specific to a give SSID.
These rules are applied when traffic hits the AP prior to being sent over a site-to-site VPN.
MR Firewall Rules - Cisco Meraki
So all network traffic on that SSID will have the rules applied to them, regardless of whether it will end up traversing the site-to-site VPN or going directly to the Internet.
The AP doesn't need to be in bridged mode for the rules to be applied. For example, the NAT mode configuration suggests adding additional L3 firewall rules
NAT Mode with Meraki DHCP - Cisco Meraki
As a point of difference, firewall rules configured under "Security and SD-WAN" are enforced on the MX device and is where you need to look at traffic destined for Internet vs Site-to-site VPN.