No. There are roots and you can install any root you like including one you create. Is that some amount of centralization? I don't think so though convenience and efficiency encourage it on a single and not very important dimension. Once a CA signs a cert they are no longer involved in the HTTPS protocol and really that's the bulk of the use case. As GP noted, it certainly includes "without a single party having access to your sites visited".
How does that work? AFAIK there is always a root authority.