Abstract
Numerous analysts have conducted industry surveys and reported that there is generally a strong correlation between organizations that are growing rapidly with an increase in the number of identities managed for access and breach rates, but this correlation has not been explored statistically, as has been done for other factors, such as Poisson regression on negative binomial regression, used in the empirical information-systems security literature. This paper uses two complementary empirical exercises. We systematically de-dupe and compile quantitative statistics about identity proliferation and breach incidence due to AI from 11 independent industry surveys and reports that were published in 2025–2026, and combine the direction and approximate intensity of the reported connection. Second, there is no public, organization level micro dataset which allows an association of growth in AI with breach results, so we create a ‘synthetic organizational panel' (N = 500), whose generative parameters are constrained to the ranges reported in that survey evidence, and employ Poisson and negative binomial regression models of the type used in earlier empirical studies of breach determinants. A high versus low subgroup contrast, similar to that published by an industry survey of large panels, with a bottom/bottom half breakpoint in the AI-growth index, has a directional association with breach counts (negative binomial incidence rate ratio = 1.81, 95% CI [1.48, 2.19] p < .001) that is significantly larger than the rate ratio reported by the top/bottom industry comparison (approx. 3.9), which we also simulated using these Hub and spoke size breaks. A negative binomial incidence rate ratio association of an AI driven identity growth index to the number of breaches (6.15, [3.42, 11.06]) shows a significant directional association with the number of breaches, and using a top/bottom 30 panel of the AI-growth index yields an approximately 3-fold increase in incidence rate ratio (1.81, [1.48, 2.19]), which is directed towards greater breach rates than the actual breach-rate association (approx. 3.9) report by one large industry survey. These results are not offered as evidence of the causal effects of real organizations, but merely as a representative, analytically derived illustration of the implications of the results of the surveys published and are presented as an explicit, quantified example of an analytical methodology that could be replicated and used to test the causal effect of real organizations and organization’s in real experiments.