zhengzhao liu Thanks for posting your question in Microsoft Q&A. For stv2 Internal VNET mode, we recommend the following minimum NSG rules, and I couldn't find the requirement for outbound connectivity to Internet. Here is doc reference: Configure NSG rules.
So, I don't think outbound to internet is required since your backend APIs are within the subnet. If you can share where it was mentioned as required would be helpful. If you are force tunneling traffic to on-premise firewall, then check out https://learn.microsoft.com/en-us/azure/api-management/api-management-using-with-internal-vnet?tabs=stv2#force-tunnel-traffic-to-on-premises-firewall-using-expressroute-or-network-virtual-appliance as well. I hope this helps and let me know if you have any questions.