It cannot. That's the whole point of the GDPR. It forbids tracking without informed, explicit user consent. Users cannot be informed or agree with the header setting.
Sites can, of course, not track users, or not track users who set do not track. They don't want to, that's why they try to annoy and/or mislead anyone into agreeing with their horrible banners.
(Using Cookies for site settings or even logins can be done without explicit consent and without banners)
In it's simplest form it says: if you want to collect more data than is required, you have to ask users for consent.
This applies in equal measure to sites, banks, grocery stores, shopping malls, shit processing plants, nuclear reactors etc.
But there is a need for clarification here for the most often encountered consent case: web sites.
Basically the regulation could say: you must have consent to collect data, but you must ALSO observe specific standardized method X of of blanket disallowing all consent in specific contexts. For example, "if do-not-track is used in a web browser, then the user should not be shown a consent dialog but instead provided the service as if they had rejected the consent dialog".
I realize that regulators (for good reason!) are very reluctant to specify specific technologies. It's not their home turf, and it's likely to be quickly outdated. But I'm ready to accept that this would be a time when there is a good reason to make an exception to that rule.
GDPR requires that the user is able to refuse non-essential cookies. A banner, if used, needs two buttons, "Accept" and "Refuse" or something similar. Refusing should be as easy as accepting. And you MUST not serve the cookies unless the user really clicks on "Accept". This means that by default your website must work without those cookies.
So, if you want to honor the "Do Not Track" header, all you have to do is not show the banner at all, and don't use cookies that the user should be able to refuse. Done. You're compliant.
Why companies don't do it? Because companies want to force users to accept tracking. Cookie banners are nothing but a dark pattern, period. GDPR doesn't mandate them.