First, there is no sane way to grant permissions "just for a few minutes" rather than forever (unless revoked). E.g. a banking app that has a screen with nearest ATM locations doesn't need GPS access granted all the time - only when I ask for the directions.
Then, there are apps that ask for just about everything (a long sequence of "grant AppName access to something") at startup. It's a subjective opinion but I believe this sort of "fix" to deal with the new permission model on SDK update was quite popular, as I saw it relatively a lot.
And it's good if denying access is an option and you just aren't asked the same thing again until you either give up or kill the app. It's probably not an issue if that's some flashlight app you can uninstall without even thinking about it, but isn't so much when it's an app from your mobile network, allowing you to manage your plan, or something unique enough to be considered valuable.
I see only two options how to fix this for real. First is more and more regulations. Second is improved app isolation and permission spoofing (silent mic input, empty contact list and filesystem, no persistent identifiers across reinstalls, etc), and activity indicators "app is trying to access the camera right now", "app had accessed your contact list recently" that would both raise alarm or allow to grant access, depending on the end-user decision.
I don't remember when iOS did this retroactively, do you have an example? When have they even added a new permission that wasn't a new API entirely?
Also, Android permissions are strange. Like, why does an app need access to Contacts to use my Google Account to sign in? An account is not a contact and just because I want to let you unify my logins, that doesn't mean I want you to have access to my contacts.
It is true app makers are happy to ignore recommendations, but users with M+ are much more empowered. So, for example, if the app makes permission requests repeatedly, on the 2nd ask Android will provide the "Never ask again" check to auto deny permission requests. So if an app is being annoying about a permission you (the Android user) don't want to give you can silence the app.
Also, you can always deny individual permissions after you've granted them, which also includes apps that don't target M+. So if you don't think an app should require the Contacts permission then you can deny only that permission. You can argue that this is a "power user" feature, but if you're interested in app permissions I think M+ gives you the appropriate levers. And surprisingly, I've seen the developers who fix their app if enough users uninstall it and leaving a review citing poor permissions.
However, you don't really address my concern that Contacts is grouped up with Accounts when it shouldn't be. I cannot deny an app access to my contacts while allowing it to use my account to sign in. Android app permissions need to become much more granular and fully backwards compatible.
Ironically, I'm sitting here not upgrading my phone to Nougat because I really dislike the material design aesthetic of the UI. It's ugly, blinding white and turns every icon into boring circles. It also apparently breaks a lot of stuff that I use everyday.