In a lot of cases your AWS account being compromised is going to open you up to having any encryption keys you use for GPG encryption stolen too anyway. So it seems that there's a decent chance that even GPG encryption is just protecting you from the "disks stolen from the datacenter" risk.
At the end of the day your AWS account is often the "master key", so make sure you use a good password, rotate it, and 2-factor auth.