The cookie laws and GDPR are hampered by malicious compliance, sure, but also outright intentional non-compliance. What's needed is more efficient oversight and enforcement.
Malicious compliance is to make cookie acceptance much easier than refusal. Lack of oversight doesn’t punish this. Now, the incentive is to make life hard for people who decline cookies. That results in more annoying pop-ups.
That isn't malicious compliance, it is just non-compliance. If the equally difficult rule wasn't there then it would be malicious compliance.