It is indeed malicious compliance: https://european-union.europa.eu/cookies_en
I have to assume that this is the work of some contractor (Intracom?). Every cookie could be removed (analytics, etc.; and does europa.eu really need to embed a dozen of American services instead of just using <video>?), and the necessary ones could be consented to at the point of creation without any general interruption ("[ ] Remember Me (stores a 30-day cookie)" during the login flow).