GDPR does not mandate specific technical solutions.
But actually honoring DNT properly would immediately mean no consent banner, but the consent banner is there to fool you into giving up your rights while providing (flimsy) legal cover for the company.
The banner is also there to make you complain about EU bureaucrats, for having the law changed. And it works: Outrage is often on EU cookie banners, not in people selling our data.
While this is true, the EU does have a tendency to step in and start enforcing technical requirements if the industry doesn't respond. USB-C, for instance, has been standardised, because attempts to tell the industry "one plug, you people figure out which one" didn't work.
It's still early days for the GDPR (relatively speaking), but I can see the EU enforcing a particular privacy-related mechanism eventually.
It also doesn't help that DNT is just a boolean signal, it doesn't give you the control over your data that the GDPR demands.
Relatively speaking GDPR at this point is just shy of 30 years old - that's when most of the effective rules came into play.
What changed the most with GDPR is that enforcement now has teeth. Not as big teeth as say, NIS2, which actually has executives more concerned than middle level about being compliant, but still big.
But actually honoring DNT properly would immediately mean no consent banner, but the consent banner is there to fool you into giving up your rights while providing (flimsy) legal cover for the company.