Also, if people are trained to just click them away, that's not really that bad, since tracking has to be opt-in, so if you click the banner away, you don't get tracked by default (that is, in theory; the reality is, many websites disregard this completely and have tracking cookies enabled by default)
So they are mandatory, since all websites NEED advertising revenue and analytics to function.
You can also run ad’s asking as you are not using targeted ad (which you are allowed to use if you ask for permission)
There are invasive ways of asking for such permission. Sites that do full take overs of the site or persistent bars that follow you around are just trying to annoy the user into clicking agree.
Why does the European Commission's website want to track me? They have a banner, too. In fact, I have yet to visit an EU government website that doesn't have a banner.
GDPR has the great idea that you shouldn't be tracked unless you consent. The popups are a way of forcing consent because users just click through them. However, the default should be that you're NOT tracked and opting in should be explicit, which possibly means all those popups that begin tracking you after one click are not compliant. Then I've also seen sites where opting out is difficult - there's a hard to find link that takes you to some settings page where you need a dozen clicks to disable tracking cookies. That's definitely not GDPR-compliant.
Despite the practical annoyances, I direct my frustration at the cancerous advertising industry that has turned the Web into a giant ad platform, and so the industry is very intentionally undermining GDPR protections.
It's covered by PECR. There's a good overview of the rules here: https://ico.org.uk/for-organisations/guide-to-pecr/cookies-a...
The main change GDPR brought to it (as I understand it) is that it introduced stricter rules about how consent works. But even though GDPR doesn't specifically require cookie warning, it does require that you get informed consent from people before you store personally identifiable information about them; in many cases this effectively means getting their permission before using tracking cookies.
So tl/dr, it's primarily PECR that covers cookie handling, but GDPR also plays a role.