As far as I can tell this basically means that all apps must be approved by Apple to follow their “platform policies for security and privacy” even if publishing on a third party app store. They will also disable updating apps from third party app stores if you stay outside the EU for too long (even if you are a citizen of an EU country, with an Apple account set to the EU region).
The idea that preventing app updates is in line with their claims of protecting security is utterly absurd. “Never attibute to malice what can be explained with stupidity,” but Apple isn’t stupid.


You upload the binary to the App Store, and as a part of the release process they may inspect the binary to figure out what it’s doing.
They of course don’t do that for everything as it’s a bit complicated to do for everything, but it can be an effective means to for example figure out when an app is calling an API in a prohibited manner.