The network isolation is somewhat interesting...but it makes me wonder why non-"private" AWS services aren't already isolated at the network layer. There's no reason why they couldn't be. They already control everything that goes in and out of every virtual machine in their data center, there's no reason the default should be for any machine to be able to talk directly to any other machine.
My guess is the warm secure feeling will last until the new security tradeoffs of cloud computing become better understood a few months from now. But since so much is about perception, this is a clever move.
But I think it is more than only addressing perception - the alternative until today was building your own VPN by hand and dealing with all those dynamic IP addresses. Very awkward and error prone...