Are you sure that out-of-the-box GA requires it? I thought the only info it recorded was anonymised.
I guess you may actually make it truly anonymous from a GDPR point of view if you proxy all calls through your own server and strip out anything that can be used to reidentify a user - so no IP addresses, session IDs, etc.
And even then it might not be strictly compliant due to Schrems II ruling