If WSUS is in use and GPOs point the computers there, YOU are the one responsible for approving the updates. If you don't approve any updates, or you don't sync the correct products/classifications, the computers will not get the updates they need. If you do approve any updates, the computers will only find their needed updates and install them according to the GPO settings (4 automatically and the appropriate setting, or 3, manual and wait for install).
What is your goal here?
I'd recommend reading through my 8 part blog series on How to Setup, Manage, and Maintain WSUS - part 4 deals with GPO Policies.