Verdict
Move the compute. Keep only the managed services you actually use.
For most teams the right play is not "leave AWS entirely". It is to recognise that an EC2 instance is fungible compute — there is no good privacy reason to keep it on a US identity-bound platform when the same shape of compute is available KYC-free, flat-priced, and with no egress charge under constitutional Nordic protection.
Move the compute first. If you depend on RDS, S3 or Lambda, keep those on AWS — there is no managed-services equivalent on NordBastion, by doctrine. As your stack moves from “AWS-everywhere” to “infrastructure-I-own”, the bridge shortens; some teams complete the move in a quarter, others run a hybrid indefinitely.
NordBastion will not be everything AWS is. It will be plain compute, flat-priced, KYC-free, pinned in one of four Nordic legal regimes with a published canary, and that is exactly the part you came here for.