Yes, they still need to audit and whitelist the builds of GrapheneOS. That's what "standard APIs" are - they identify a build of OS, but someone still needs to make sure it's secure.
If you don't want Google to do that for you, then the app developer has to.