Of my understanding that falls under the PECR not GDPR, the ICO state you should "get consent the first time you set a cookie", meaning you should get a positive action to confirm such as a tick box or button, however they also state that you can get implied consent which doesn't require an "opt-in" this is the big grey area.
You also have the EU Cookie Law that should enforce the right for a user to be able to request information on what you store and why, and if you can't provide an answer that is satisfactory (again vague) then the user has the right to report you, presumably to the ICO which at that point would fall under GDPR.
I've not really answered your question, but hopefully it gives you some more information.