Full AWS Practitioner Certification Question

A technology company hosts its web application on Amazon EC2 instances distributed across multiple Availability Zones. These EC2 instances reside within private subnets. The architecture includes an internet-facing Application Load Balancer (ALB), and the EC2 instances are registered in the ALB's target group. Despite this setup, users on the internet cannot access the application. What changes should a solutions architect make to correct this connectivity issue while maintaining the existing security boundaries?