Well, that assumes that the ID is cryptographically random. Perhaps that is a bad assumption.
Odds are that an account wildcard match like 676363687* will just match a few hundred entirely random AWS accounts.
Honestly, wouldn't surprise me that much if they were willing to accommodate this if for sufficiently large accounts. It'd still pretty sketchy to design your access control around, but it wouldn't be unrealistic.