It's not quite that hard. Hypothetically, you have a digital certificate, signed by the government, for your VPN provider with a list of VPN endpoints. Your client presents that certificate to the ISP, unblocking ports in that specific instance, to those endpoints. Otherwise, all common ports are blocked, and anything that smells VPN-y gets throttled.
Alternatively, the UK could have a self-service whitelisting system, when a legal entity signs a contract stating that traffic inside the tunnel is also filtered, at the endpoints listed.
Also: The UK government, believe me, does not expect 16 year olds to be capable of spinning up EC2. And if somehow they do, how are they paying for it?