Is apparmor default deny?

Is apparmor default deny? For example consider the case under SELinux in enforcing mode, where I install a package with no policy associated with it. SELinux’s default behaviour is to deny all syscalls that application makes. Does apparmor work the same way, or do you need to explicitly create the policy first and install it.