Sometimes there exist data or processing residence requirements that bind you to a specific region (e.g. EU-only). Also, „all AZs in this region no longer exist“ is not on everyone‘s bingo card, this is a good reminder why multi-AZ deployment in the same region may be not enough.
For data center guys this is definitely a case study, because drone attacks are probably on the threat list for everyone now, for various reasons, including domestic terrorism and hybrid warfare. If you want to defend your investment, time to think what covers you from the air.
It's an open question at what point we'll start seeing small fiesty startups that want to sell you a privately owned air defense system for your datacenter roof. The tech to do it is probably far ahead of the regulatory regime to own and operate autonomous small radar+SAM batteries.
It heavily depends on "what kind of DC". A lot of current DCs are not really well protected against a lot of known threats - and that's just a design tradeoff.
High value data is already protected a bit better (or at least should be - the usual trend, management gets lazy when nothing blows up). I'm old enough to have sat in the meetings for "so, apparently a plane crashing into one or more of our locations is a viable risk now" - and a DC hardened for "somebody tries to land a 747 on that thing" should also survive a small drone with a bit of explosives.
While for the younger ones the "we lose several availability zones within days" is a new thing now - it really isn't. We were planning for that back then as well, just that we didn't call it "availability zone" or "cloud" yet.