Usually the rule is just "provide a digital signature with key X", or some threshold of keys. Though they can be more much complicated, and even simple scripts can have powerful applications (e.g. https://bitcoincore.org/en/2016/02/26/zero-knowledge-conting... )
The flexibility is nice but there are some gotchas-- Your rules are included in the transaction, storing and transmitting expends system resources, costs you fees, distinguishes your transactions from other users, and in doing so discloses information about your business practices.
Taproot addresses this by doing some relatively simple elliptic curve crypto magic to effectively hide the conditions inside a public key without impairing it or making it larger. Then, if the parties transacting cooperate they can keep their fancy conditions private and just sign using a single jointly controlled key. If the parties don't cooperate some of the conditions may need to be exposed, but only the absolute minimum to show the transaction is allowable. Cooperation is likely however, because non-cooperating won't create a benefit.
The effect is that instead of being limited to a few thousand bytes of operations for the rules governing your coin, you could have gigabytes of rules, and yet never expose them (and burn network resources and your privacy) -- or if you do need to to expose some of them, you only need to show a small amount. ... and as a bonus have your transactions look just like a really boring maximally simple wallet's transactions.
There are also some small efficiency gains: somewhat smaller signatures and making batch signature validation possible.
It's a little difficult to estimate the impact this improvement will have: Most users only use relatively simple rules, and as a result they will just become a little more private and a little more efficient. But if taproot was marketed like most altcoins are the headline would be "Taproot increases script expressiveness FORTY ORDERS OF MAGNITUDE while reducing resource usage!", because-- indeed-- you could make a script that was 1.3e41 times larger than the current rules allow if only you had a computer powerful enough to handle such data locally. :P So for common uses it's a small to moderate efficiency and privacy improvement, but it could enable some new and interesting applications.
... and you might not ever know about some application that benefited from it, because unless you're a party to its transactions there may be nothing identifying published about them. :) Not the best for marketing, but better for human rights.