It is completely not true that you can "offload" responsibility as described. If you run a website, then you are a "controller" and are responsible for ensuring that processors are also abiding by the GDPR, for example by securing Data Protection Agreements and vetting the processors.
There is definitely risk associated with running third party analytics and not having opt-in associated with that. It is very much not established whether GA's solution is good enough. Having said that, while there is a risk, at this point it seems to be a small risk of getting into GDPR trouble unless you are a very large operation.
That's what I tell my clients. YMMV.