You don’t have to, what happens between a user and their browser is theoretically none of your business. But if you care about your users’ privacy, I see no reason not to send this header as there’s no defined value for you as a business (unless you plan to somehow try to retarget users who’ve visited your site based on guessing which cohort that potentially refers to).
The user opts in to being placed into a cohort. The site opts out of providing information to Google to let them generate cohorts based on the site. There’s no overlap.
Has anyone stopped to consider where laws and regulations should come in to say that tracking like this is far too invasive?