I was working at Google at the time. Before Llama, releasing weights was not even worth a discussion.
You did have to apply for access, but if you met their criteria (basically if you were the right profile of researcher or in government), you got direct access to the model weights, not just an API for a hosted model. So access was restricted, but the full weights were shared.
I believe that the model was leaked by multiple people, some of which didn't work at Meta but had been granted access to the weights.
Funny how ByteDance kicked both their asses so hard at RecSys algos, they had to go back to the drawing board to meet the newly redefined expectations on the quality of short-form video recommendations.
Unlike common benchmarks for LLMs.