This is a 'customer cost reduction' issue.
A user should be able to optionally to use the the aws/s3 kms key, and to configure it as the default key for the bucket created.
Here are the relevant docs:
https://docs.aws.amazon.com/AmazonS3/latest/userguide/default-bucket-encryption.html
https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-key.html