It doesn't protect you meaningfully as an EC2 user, since there's no (current, on AWS) way to do an "encrypted VM" where everything including memory is encrypted and the hypervisor can't be coerced into decrypting it en masse.
It does protect you for S3 if and only if you conduct the crypto outside AWS and generate/manage the keys yourself (e.g. how tarsnap does it). It may protect you for some of the other AWS services IFF you use them in the same hybrid way, but I don't know of anyone who uses AWS's database services without just using EC2 nodes primarily to talk to them.