If FullAWSAccess is granted, the accounts in that OU will have these permissions for everything that is not also limited with any Actions that are Denied.
If there is a child OU in that OU, the FullAWSAccess permissions will be available to accounts in that child OU, but that child OU will still have to grant the specific permissions to the account under it.
If you were to put FullAWSAccess on the OU, and only attach EC2 and S3 on the child, accounts in the child will only have EC2 and S3.
I hope that helps.