It's not about storing off-chain, you compute off-chain and post to the network a cryptographic proof of the computation.
Rollups provide something akin to lossless compression proofs of computation. You execute the computation off-chain with high throughput and post a proof to the Ethereum network, this proof contains everything necessary to verify the correct execution of the computation. Sounds mind-blowing but we can thank smart mathematicians for figuring out the cryptography that makes it possible.
This means that we can scale off-chain while enjoying the security guarantees of the blockchain.
These techniques allow scaling the network throughput towards the 1000-4000 transactions per second range. Which together with data-availability sharding will push the throughput towards the 100K transactions per second range.
To be noted that this is not anymore a theoretical construction, these things are live running today on Ethereum. You can check the different solutions as well as detailed explanations of their trade-offs, limitations, etc... Here: https://l2beat.com
What is and isn't art and artistic value, and whether an indistinguishable copy of the mona lisa should be valued the same is an entire discussion, yes, but it isn't tied to NFT-s. By the way when I say indistinguishable I don't neccessarily mean by world class experts, but for example my guests who happen to spot my (hypothetical) fake mona lisa in my living room.
Edit: yes I have only NFTs as defined in Ethereum in mind. If there are other solutions working better/safer, I am not aware of them...
I would agree that an NFT pointing at some plain HTTP(S) URL on some random server without so much as a hash to identify the original content is pretty much worthless.
From the chain perspective they never really leave the chain. They are either locked (most L2 solutions such as Bitcoin Lightning) or they are held by someone else (most centralized custodians, including exchanges). So the worst that can happen is that the locked/held coins get "stolen".
As I understand it, the idea is you put the data itself off chain but keep hashes on chain. Anyone who downloads the data can verify it by checking that the hash matches what is stored on chain.