if the tag just sent out it's serial number, then someone would be able to set up a sniffer, and if they saw tag number 3 and saw you standing there, they would be able to connect that you were carrying tag 3, and then be able to figure out that anytime they saw tag number 3 that you were around. (just using a simplified number, obviously the actual serial is longer and has letters)
so instead of broadcasting the serial, it has a way to randomly pick a number so that apple and the tag stay in sync. So anyone in the middle would just see a random number that they can't connect back to your tag, but apple can. If you've used an authenticator app on your phone that gives you a 6 digit number that changes every minute or so to log into a web site, it's a similar thing.