Right, and then the legal teams tell me they don't care, and we should put up the cookie banner anyway. I feel like you didn't read my original comment.
I've built software used by EU governments, and we don't use a cookie banner for our login cookies either.
If your legal team genuinely suggests that, it's likely your company uses the login cookies for some additional purposes.
That just means your legal team is lazy or incompetent. I work for a massive company that handles extremely sensitive PII and we don't have a cookie banner, because we don't need to have a cookie banner. GitHub doesn't have one, Gitlab doesn't have one.