It's not particularly clear who has to change anything to comply.
As I understand it you are only really on the hook if your cookies store personal information and transfer it when it's not strictly necessary for the operation of the service. Which could apply to all cookies, or no cookies. Is it strictly necessary to use cookies to have a users login name remembered? No. There are probably other ways but the one that immediately springs to mind is a much worse violation of privacy. A database of IP addresses' and associated usernames.
I think it's mostly people like Google/Twitter/Facebook that are liable for it. Receiving (or being tracked by) cookies that don't come directly from the site you are on but through a snippet of code that does Ads or Facebook likes or whatever. That's not immediately obvious to the user and it's not strictly necessary for the operation of your website/service. However it is strictly necessary for the operation of the Adsense system and anyone using Adsense must already have that bit of DART ToS on their site somewhere.. so is it just a case of Google updating that?
A tick box that says 'remember my username', that sets a cookie that doesn't get sent outside that site.. seems to fall within the realm of 'strictly necessary' AND is by it's nature asking the user for permission. So I think that's exempt.
Pretty much the only cookies that this law effects seems to be exactly the kind that deliberately avoid detection. The malicious types. Are the pop-up merchants really going to start asking permission before they fill your mum's computer with trash? Doubt it.
http://www.ico.gov.uk/for_organisations/privacy_and_electronic_communications/the_guide/cookies.aspx