We ended up with cookie rules because regulators were concerned about the use of cookies to create user profiles based on activity across multiple websites, especially for "evercookies"/"zombie cookies" where a user's cookieID would be resurrected even after a user deleted them. Instead of banning zombie cookies or cross-site tracking, the EU instead decided it was a violation of user privacy to place any cookies or other data files on the user's machine without their consent.
The actual language is "Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information."
Cookie consent boxes are implemented at the website level because the law applies to website publishers, not browser makers. Website publishers were explicitly told that they cannot rely on a user's browser settings. This put the browsers in the back seat and ended up with today's world where you have to opt out of a service provider like Google Analytics on a site-by-site basis.
The vast, vast majority of users do not touch cookie settings. There are probably more users running scripts to disable cookie popups than there are users opting in or out of specific cookies.
It is an odd world where websites bend over backward to make cookie popups that actually work knowing full well users do not care. The average user doesn't really know much about cookies, much less the wide variety of activities powered by cookies. Cookie consent popups are publicly available, making them easy targets for regulatory audits. Ireland ran a huge sweep and sent out letters to a number of large companies telling them to clean up their act by October or else. We are a few weeks away from seeing what the "or else" will be.
I'm happy to answer any other questions you have on this.