Earlier quoted context omitted.
They're not covering their ass, they're making a deliberate tradeoff. It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen. And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie…
Every site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases. They could have instead targeted it, and applied it, to third party ad providers only, like Googl…
And if you decide you need them, you can do them server side. That's not as good? Oh well. See above about want vs need.
Why not just make a Google law? Because Google is far from the only abuser. Using a VPN that routes through Europe is a real eye-opener. At least whatever country I got routed through apparently required that cookie banners include a list of every single partner who got your data. Pretty much every site had hundreds of them. One was literally over a thousand. No, the entire industry is rotten. And the epidemic of cookie banners just shows how rotten it is. They can't even be shamed into behaving.