There's no chance that anything positive will ever happen with the web again, it has gotten worse at every step for more than a decade. Especially when Google has any involvement with it.
The death of cookies is absolutely a corporate level driver for the push to authenticate.
Trackers being unable to stash long ttl cookies is being replaced by reliable ways to reidentify people... such as logging in.
Part of what's confusing here is that "first party" and "third party" are being used in a technical sense to mean which domain the cookies are set on. If on an example.com page JS from example.net causes a cookie to be set on example.com that's "first party", while if the cookie is set on any other domain that's "third party".
You should still be able to avoid a banner by having a footnote below the “add to cart” such as “we’ll set a cookie to remember this according to our cookie policy [link]”?
>> You should still be able to avoid a banner by having a footnote below the “add to cart” such as “we’ll set a cookie to remember this according to our cookie policy [link]”?
would count as consent under EU standards. I thought consent had to be indicated unambiguously. Clicking an "add to cart" button only unambiguously indicates that the user wants to add the item to their card, not that they are consenting to (or have even noticed) some footnote below the button.
There are much bigger breaches of the GDPR/ePrivacy out there and entire businesses built upon them and they keep operating in total impunity.
Safari stopped supporting third-party origins setting cookies on themselves many years ago
In other words, you are seeing these because marketing departments need BS metrics that measure nothing and are based on some personal data. The internet can happily exist without them as proven by Github[1].