Always fun to hear from a bank how to cheat at something...
Even for personal accounts, consider multi account - never use root account directly, and never issue API keys from it. Just use for budget.
Service control policy - just block the ec2 instance types XXL...
Budget alerts