Using your example of a Rolex, the code can be scanned by the authorised dealer and buyer. Those events are then stored in the blockchain next to the cryptographic hashes of both entities.
Any authorised dealer who buys one for resale would scan the QR code so ownership can be transferred in the same way on a public ledger.
If there's a public record that this Rolex has been purchased already and you scan it, this record would show up. It could even show exactly where and when it was purchased.
Clearly, for someone to put a real cryptographic key on a fake Rolex, they need to have taken it from a real one.
So if someone tries to sell you a "Rolex" and you scan it, you'll have the history of the watch right there. If they try to claim it's new, you'll know that's a lie. If they try to sell it to an authorised dealer, they'll get caught.
This could still leave space for fake Rolexes to be sold as used on eBay or something of course, but then if you buy a "Rolex" on eBay from a random seller (not an AD) you kind of know what you're getting already don't you?
(Although even in those situations, knowing exactly when and where the real watch was last purchased makes it easy to just make a phone call and get a better idea of legitimacy. Currently, even ADs send the watches to Rolex for verification because the fakes are so good.)