1 Answers
I believe that this is because no decryption is needed to create a volume from a snapshot – the volume just contains the same encrypted data as the snapshot. That volume still cannot be attached to a running instance unless you have access to the KMS CMK that it was encrypted with, keeping the data secure.