Today, there's a "Block Public Access" button which basically says "I solemnly swear that I don't want anyone outside of my account to see this S3 bucket. Please don't put this bucket on the public internet, even if I screw up my bucket policy and/or ACLs"
The option is off by default, but it's easy to find, simple to understand, and doesn't force powerusers to give up control.
[0] https://aws.amazon.com/blogs/aws/amazon-s3-block-public-acce...
If they hard shut people down then people would be posting “AWS turned off my services and took my site down blah blah blah”
I actually tend to agree that, especially for hobbyist use, an automated hard cut off that cut out most further AWS service use would probably be desirable--even if some would (mis)use it in production environments and end up blowing up their site and complaining about it. I'm sympathetic to those who find the potentially open-ended nature of AWS billing to be bothersome. An alert is just an alert. There's no guarantee you'll be in a position to receive it and act on it in a timely manner.