I enabled S3 encryption on two objects. However, the "aws/s3" managed keys are not appearing in the Encryption Keys section within the IAM console.
Remember, KMS is a region service, like S3. If you don’t have a bucket in a region with encryption enabled, in the region that your viewing in KMS, then you won’t see the aws/s3 key. I haven’t used the Stockholm region yet, and KMS is completely empty for me there.
See Protecting Data Using Server-Side Encryption. SSE-S3 uses the AES-256, which is managed by S3. SSE-KMS is the KMS managed key you’re looking for.