[0]: https://aws.amazon.com/security/penetration-testing/
Also the pentesting policy explicitly states that customers can pentest without approval.
[0]: https://aws.amazon.com/security/penetration-testing/