IMO, the intent was good... but yeah, the implementation is a grand demonstration of what you get when legislators don't understand the technology they're regulating. It would be far better if they'd required browsers, not websites, to show the notifications - much like they already do when a site wants to access your webcam/mic/location/etc[0]. That would mean much less implementation work (once per browser instead of per site), no way for underhanded sites to use cookies without the user being notified or despite the user declining them, consistent UI across all sites...
Such a thing could provide significantly more useful information, too - I envisage a notification with "This site wants to use a cookie on your computer" at the top, "allow/deny, now/always" buttons and a "What are cookies?" link at the bottom, and a user-friendly breakdown of this particular case in between, things like:
• "only visible to this site" vs "visible to ad.doubleclick.net" etc - maybe including, say, the Organization Name from the cookie domain's SSL cert, at least in the case of cookies set to "Secure" (maybe only if the cert's EV)
• "until you close your browser" vs "for a week" etc - perhaps with a way for the user to force session-only if desired
• possibly some kind of warning about snooping risk if the cookie's not marked secure, or not HTTP-only & 3rd-party scripts are on the page, etc
• for the case of 3rd-party cookies, it'd be possible to list which other sites have used the same cookie in the past
And so forth. The most importantant point being that you could actually trust this information - your browser has no motivation to lie to you about it, but any random site might.
[0] eg, https://i.imgur.com/NcxWz8zh.jpg