[Google Cloud docs (Vector Search private services access)]: Vector Search online queries inside your VPC need private services access with a /16 subnet sized for them, advertised from Cloud Router as a custom advertised route. Then update the VPC peering connection to export custom routes to the service producer network. By default the service producer only learns subnet routes, so anything not from a subnet IP range gets dropped. That peering export is the bit people miss.

Context: Google Cloud docs (Vector Search private services access): online queries need private services access set up with the right subnet sizing. Size the subnet at /16 for Vector Search online queries and advertise it from Cloud Router as a custom advertised route. On VPC Network Peering, update the peering connection to export custom routes to the service producer network. By default the service producer only learns subnet routes, so any request not from a subnet IP range gets dropped.