We have similar scenario, we have 7000 concurrent users, and nerly to 700 aps. We deploy vlan model to the port of the ap that have the vlan for ap and a lot of vlans to deploy the topologies.
We are 802.1x and the next step is autentication using the AP and not the controller. Then if there are any problem with the controller all B@AP works perfectil. We can do this because we have six routing domains and only one controller (HA).
with 38xx ac you have mora traffic, and with ac wave2 MU-MIMO i think we will see increased the traffic of the users.
thanks for your info.