At some point it was definitely more than 95% of websites being shady with their cookie coercion banners.
That is why it is important to have sandboxes and/or laws that are based on size, number of consumers, etc. one thing is to ask for a full GDPR compliance to a bank and much different is for small companies.
In the EU, it's basically expected that the courts will apply the law on a case-by-case basis, which opens the door to inconsistent application of the law and ultimately to selective prosecution.
In the case of Meta, it definitely seems inconsistently applied (even though I hate Meta and would never trust them again). They simply choose the seemingly worst offender (Meta) and try to kick it out of the EU, while leaving alone the actual worst offender (ByteDance). Prosecution becomes a case of politics rather than justice.