https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
This page says these. What do these mean exactly? Are there any problems caused by this limitation?
Ideas
The instance role is not a service-linked role. The only service-linked roles for EC2 are for Spot Instance Requests and Spot Fleet Requests. Thus you can't bypass SCP with instance role. Same for ECS and Lambda roles.
Not sure I understand the question, but service-roles are assumable only by an AWS service. They are not for IAM users, groups or IAM roles.