Here’s what I expect:
If the Internet Kill Switch is enabled, then NO traffic should go through the ISP.
If VPN Policies (eg, exceptions) are then added, then NO traffic should go through the ISP until these are APPLIED (ie. the Apply button is clicked).