Reminder that we've already had a spec for it. In the 90s! And it even has been implemented in the Internet Explorer: https://www.w3.org/P3P/ It did absolutely nothing for privacy. Google has been sending bogus P3P headers that broke IE's implementation and allowed all cookies. Adtech companies don't want users to have an easy opt-out. They didn't want P3P. They didn't want DNT. They will not want this new spec, unle…
What is different this time around compared to P3P, DNT, and other earlier mechanisms is that the times have changed. Privacy is a much bigger topic. There is much more reporting now about privacy. Users understand a bit better better (though, we are still far off from real transparency). Lawmakers and regulators are catching up. Many companies embrace privacy. There is a burgeoning privacy tech industry with quite a bit of venture funding.
Also, lessons were learned from earlier efforts. CalOPPA required recipients of DNT signals to only say whether they respect those. The CCPA regulations now require actual compliance. If the CCPA is applicable to your company, you have no choice but to respect it. And that is also true for automated browser signals. There is much stronger enforcement now behind more recent privacy laws. Virginia and Colorado recently enacted privacy laws, and it is likely that other states will do to.
Disclosure: I am an academic researcher working with collaborators of all stripes on Global Privacy Control (GPC) [1, 2]. We are in touch with the good folks at ADPC and support their work. They are doing a fantastic job over there!
[1] https://globalprivacycontrol.org/ [2] https://github.com/privacycg/proposals/issues/10