On AWS RDS, you can't turn off encryption once you turn it on.
The encryption secret keys always stay with AWS and all you can download are the public keys.
So I'm not so sure what's the point of encryption at rest in AWS except just to tick off a compliance and regulatory checklist.
The private key is with them anyway, just don't encrypt and save few milliwatts of power.