Every cost conversation wants to be about architecture: reserved capacity, spot, moving to a different service, redesigning for serverless.
The actual biggest lever, repeatedly, was that instances were sized against what somebody requested at provisioning time rather than what the workload used. Reading utilisation and resizing accordingly required no architectural change and no risk.
Second largest: stopping non-production environments outside working hours. A development environment running twenty-four hours a day for a team that works eight is paying for two thirds of nothing.
Neither is interesting. Both should be done before anything clever is discussed.