I asked AWS to separate the two accounts (which is a thing they can do!), and the response I received a week later was:
After carefully reviewing your request alongside the Service Team, we are unable to separate your AWS and Amazon.com accounts. Having said this, please note that we continuously evaluate eligibility for this separation process. While we are unable to provide you with a specific timeframe that your account may be eligible, we may automatically complete the separation process for you in the future.
What does this even mean? Has anyone had this experience before, and, if so, how did you get this resolved?
For instance, in the past month I received this notice, unprompted, from amazon:
Greetings from Amazon Web Services,
In the past, you have used the same email address and password to sign in to Amazon.com and AWS. In response to customer feedback, AWS is updating your account to make your access to Amazon.com and AWS independent. You can continue using this email address and your current password to sign in to Amazon.com. However, the next time that you sign in to AWS, you will be prompted to create a new password and will have the option to register a new multi-factor authentication (MFA) device. MFA is a best practice that adds an extra layer of protection on top of your email and password.
I'm not an expert at this, but my coworkers claim to have moved production systems to new accounts when dealing with changes of project stewardship, funding, or accounting.