But my tl.dr. as I understand it is that IAB provides a Transparency Consent Framework[2] to its users, which includes popup cookies.
They lost a case where they argued they don't have any responsibility ( to the degree that they didn't even have a Data Privacy Officer or had done a Data Privacy Impact Assessment) for providing the IAB compliance popups. These popups were used by others in order to do gain "consent" to do real time bidding ads (and probably other things), it might be that they also provided some level of RBT.
They lost and the court said they are jointly responsible and need to fix long list of things and pay 250k euro.
IAB then appealed and the appeals court deferred it to the ECJ, who has now said that yes they do have a join responsibility.
So as I understand it, this is sadly not the death-blow to valid or invalid consent popups. But at least it might improve the UX on them.
[1] https://web.archive.org/web/20240109014435/https://www.gegev... [2] https://iabeurope.eu/transparency-consent-framework/