GDPR deals with identifiers that can tie data to a single individual. Cookie IDs are just one way of doing that, true.
That's why GDPR is so powerful and a well thought out regulation. Replace the technology completely, but GDPR still applies as user-unique identifiers are still used. ex, cookie with fingerprint.js, nothing really changes. You still need to ask for consent for user-level tracking.