@Cedric Ahlers Thanks for your patience on this I am summarizing our conversation and posting the same as answer for the benefit of other community members.
Based on the information shared, vnet integration with Standard V2 apim instance will workout for your requirement.
As called out in the documentation here, using Vnet Integration you can restrict Outbound request traffic can reach APIs hosted in a delegated subnet of a single connected virtual network.
Regarding this question:
what does the APIM route through this Subnet ? Whole RFC-1918 ? The routes know to the Subnet (+UDR) or just the address spaces of the VNet ? Do you know that ?
I have checked with internal team on this, and they confirmed that all the traffic will be sent through your virtual network using a private Ip address from the delegated subnet of the Vnet.
Hope this help, let me know if you have any further questions on this.
Please accept as Yes if the answer is helpful so that it can help others in the community.